chiark / gitweb /
debian/: Use `dh_python2' for packaging.
[catacomb-python] / key.c
diff --git a/key.c b/key.c
index a7d36218ab998cbe03ebd39c78aad9522a87b1e7..c5b0ac042bfc8bfaa420b921c144256aaaa78dda 100644 (file)
--- a/key.c
+++ b/key.c
@@ -1,13 +1,11 @@
 /* -*-c-*-
- *
- * $Id$
  *
  * Key files and data
  *
  * (c) 2005 Straylight/Edgeware
  */
 
-/*----- Licensing notice --------------------------------------------------* 
+/*----- Licensing notice --------------------------------------------------*
  *
  * This file is part of the Python interface to Catacomb.
  *
  * it under the terms of the GNU General Public License as published by
  * the Free Software Foundation; either version 2 of the License, or
  * (at your option) any later version.
- * 
+ *
  * Catacomb/Python is distributed in the hope that it will be useful,
  * but WITHOUT ANY WARRANTY; without even the implied warranty of
  * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE.  See the
  * GNU General Public License for more details.
- * 
+ *
  * You should have received a copy of the GNU General Public License
  * along with Catacomb/Python; if not, write to the Free Software Foundation,
  * Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
 
 #include "catacomb-python.h"
 
+/*----- Exceptions --------------------------------------------------------*/
+
+static PyObject *keyexc;
+static PyObject *keyioexc;
+static PyObject *keyfilebrokenexc;
+
+static PyObject *kxmeth___init__(PyObject *me, PyObject *arg)
+{
+  int err;
+  PyObject *x = 0;
+
+  if (!PyArg_ParseTuple(arg, "Oi:__init__", &me, &err) ||
+      (x = PyInt_FromLong(err)) == 0 ||
+      PyObject_SetAttrString(me, "err", x))
+    goto fail;
+  Py_DECREF(x); x = 0;
+  if ((x = PyString_FromString(key_strerror(err))) == 0 ||
+      PyObject_SetAttrString(me, "errstring", x))
+    goto fail;
+  Py_DECREF(x); x = 0;
+  if ((x = PyString_FromString(key_strerror(err))) == 0 ||
+      PyObject_SetAttrString(me, "errstring", x))
+    goto fail;
+  Py_DECREF(x); x = 0;
+  if ((x = PySequence_GetSlice(arg, 1, PySequence_Size(arg))) == 0 ||
+      PyObject_SetAttrString(me, "args", x))
+    goto fail;
+  Py_DECREF(x); x = 0;
+  RETURN_NONE;
+
+fail:
+  Py_XDECREF(x);
+  return (0);
+}
+
+static PyObject *kxmeth___str__(PyObject *me, PyObject *arg)
+{
+  long err;
+  const char *errstr, *errtag;
+  PyObject *x = 0;
+  PyObject *rc = 0;
+
+  static const char *const tab[] = {
+#define ENTRY(tag, num, str) "KERR_" #tag,
+    KEY_ERRORS(ENTRY)
+#undef ENTRY
+  };
+
+  if (!PyArg_ParseTuple(arg, "O:__str__", &me) ||
+      (x = PyObject_GetAttrString(me, "err")) == 0 ||
+      (err = PyInt_AsLong(x), PyErr_Occurred()))
+    goto done;
+  Py_DECREF(x); x = 0;
+  err = -err;
+  if (err >= 0 && err < N(tab)) errtag = tab[err];
+  else errtag = "<unknown>";
+  if ((x = PyObject_GetAttrString(me, "errstring")) == 0 ||
+      (errstr = PyString_AsString(x)) == 0)
+    goto done;
+  rc = PyString_FromFormat("%s (%ld): %s", errtag, -err, errstr);
+
+done:
+  Py_XDECREF(x);
+  return (rc);
+}
+
+static PyMethodDef keyexc_pymethods[] = {
+#define METHNAME(func) kxmeth_##func
+  METH (__init__,              "KeyError(CODE)")
+  METH (__str__,               "E.__str__() -> STRING")
+#undef METHNAME
+  { 0 }
+};
+
+static void keyexc_raise(int err)
+{
+  PyObject *arg = Py_BuildValue("(is)", err, key_strerror(err));
+  if (arg) PyErr_SetObject(keyexc, arg);
+  Py_XDECREF(arg);
+}
+#define KEYERR(err) do { keyexc_raise(err); goto end; } while (0)
+#define KEYIOERR(name) do {                                            \
+  PyErr_SetFromErrnoWithFilename(keyioexc, name);                      \
+  goto end;                                                            \
+} while (0)
+#define KEYFILEBROKEN(name) do {                                       \
+  PyErr_SetFromErrnoWithFilename(keyfilebrokenexc, name);              \
+  goto end;                                                            \
+} while (0)
+
+/*----- Data structures ---------------------------------------------------*/
+
+typedef struct keydata_pyobj {
+  PyObject_HEAD
+  key_data *kd;
+} keydata_pyobj;
+
+static PyTypeObject *keydata_pytype;
+static PyTypeObject *keydatabin_pytype;
+static PyTypeObject *keydataenc_pytype;
+static PyTypeObject *keydatamp_pytype;
+static PyTypeObject *keydatastruct_pytype;
+static PyTypeObject *keydatastr_pytype;
+static PyTypeObject *keydataec_pytype;
+#define KEYDATA_PYCHECK(o) PyObject_TypeCheck(o, keydata_pytype)
+#define KEYDATA_KD(o) (((keydata_pyobj *)(o))->kd)
+
+typedef struct subkeyiter_pyobj {
+  PyObject_HEAD
+  key_subkeyiter i;
+  PyObject *kdobj;
+} subkeyiter_pyobj;
+
+static PyTypeObject *subkeyiter_pytype;
+#define SUBKEYITER_PYCHECK(o) PyObject_TypeCheck(o, subkeyiter_pytype);
+#define SUBKEYITER_I(o) (&((subkeyiter_pyobj *)(o))->i)
+#define SUBKEYITER_KDOBJ(o) (((subkeyiter_pyobj *)(o))->kdobj)
+
+typedef struct keyfile_pyobj {
+  PyObject_HEAD
+  key_file kf;
+} keyfile_pyobj;
+
+static PyTypeObject *keyfile_pytype;
+#define KEYFILE_PYCHECK(o) PyObject_TypeCheck(o, keyfile_pytype)
+#define KEYFILE_KF(o) (&((keyfile_pyobj *)(o))->kf)
+
+typedef struct key_pyobj {
+  PyObject_HEAD
+  key *k;
+  PyObject *kfobj;
+} key_pyobj;
+
+static PyTypeObject *key_pytype;
+#define KEY_PYCHECK(o) PyObject_TypeCheck(o, key_pytype)
+#define KEY_K(o) (((key_pyobj *)(o))->k)
+#define KEY_KFOBJ(o) (((key_pyobj *)(o))->kfobj)
+#define KEY_KF(o) KEYFILE_KF(KEY_KFOBJ(o))
+
+typedef struct keyiter_pyobj {
+  PyObject_HEAD
+  key_iter i;
+  PyObject *kfobj;
+} keyiter_pyobj;
+
+static PyTypeObject *keyiter_pytype;
+#define KEYITER_PYCHECK(o) PyObject_TypeCheck(o, keyiter_pytype)
+#define KEYITER_I(o) (&((keyiter_pyobj *)(o))->i)
+#define KEYITER_KFOBJ(o) (((keyiter_pyobj *)(o))->kfobj)
+#define KEYITER_KF(o) KEYFILE_KF(KEYITER_KFOBJ(o))
+
+typedef struct keyattrs_pyobj {
+  PyObject_HEAD
+  PyObject *kobj;
+} keyattrs_pyobj;
+
+static PyTypeObject *keyattrs_pytype;
+#define KEYATTRS_PYCHECK(o) PyObject_TypeCheck(o, keyattrs_pytype)
+#define KEYATTRS_KOBJ(o) (((keyattrs_pyobj *)(o))->kobj)
+#define KEYATTRS_KF(o) KEY_KF(KEYATTRS_KOBJ(o))
+#define KEYATTRS_K(o) KEY_K(KEYATTRS_KOBJ(o))
+
+typedef struct keyattriter_pyobj {
+  PyObject_HEAD
+  key_attriter i;
+  PyObject *kobj;
+} keyattriter_pyobj;
+
+static PyTypeObject *keyattriter_pytype;
+#define KEYATTRITER_PYCHECK(o) PyObject_TypeCheck(o, keyattriter_pytype)
+#define KEYATTRITER_I(o) (&((keyattriter_pyobj *)(o))->i)
+#define KEYATTRITER_KOBJ(o) (((keyattriter_pyobj *)(o))->kobj)
+#define KEYATTRITER_K(o) KEY_K(KEYATTRITER_KOBJ(o))
+#define KEYATTRITER_KFOBJ(o) KEY_KFOBJ(KEYATTRITER_KOBJ(o))
+#define KEYATTRITER_KF(o) KEY_KF(KEYATTRITER_KOBJ(o))
+
+/*----- Filters -----------------------------------------------------------*/
+
+static int convfilter(PyObject *x, void *p)
+{
+  key_filter *f = p;
+  const char *fs;
+  char *end;
+  int n;
+  PyObject *a = 0, *b = 0;
+  int err;
+  int rc = 0;
+
+  if ((fs = PyString_AsString(x)) != 0) {
+    if ((err = key_readflags(fs, &end, &f->f, &f->m)) != 0)
+      KEYERR(err);
+    if (*end)
+      KEYERR(KERR_BADFLAGS);
+  } else {
+    PyErr_Clear();
+    if (!PySequence_Check(x))
+      goto tyerr;
+    else if ((n = PySequence_Size(x)) < 0)
+      goto end;
+    else if (n != 2)
+      goto tyerr;
+    else if ((a = PySequence_GetItem(x, 0)) == 0 || convuint(a, &f->f) ||
+            (b = PySequence_GetItem(x, 1)) == 0 || convuint(b, &f->m))
+      goto end;
+  }
+  rc = 1;
+  goto end;
+tyerr:
+  TYERR("expected flag string or flag/mask pair");
+end:
+  Py_XDECREF(a);
+  Py_XDECREF(b);
+  return (rc);
+}
+
+static int convflags(PyObject *x, void *p)
+{
+  unsigned *f = p;
+  const char *fs;
+  char *end;
+  int err;
+  int rc = 0;
+
+  if (convuint(x, p))
+    return (1);
+  else {
+    PyErr_Clear();
+    if ((fs = PyString_AsString(x)) != 0) {
+      if ((err = key_readflags(fs, &end, f, 0)) != 0)
+       KEYERR(err);
+      if (*end)
+       KEYERR(KERR_BADFLAGS);
+    } else {
+      PyErr_Clear();
+      goto tyerr;
+    }
+  }
+  rc = 1;
+  goto end;
+tyerr:
+  TYERR("expected flag string or integer bitfield");
+end:
+  return (rc);
+}
+
+static PyObject *meth__KeyData_readflags(PyObject *me, PyObject *arg)
+{
+  const char *p;
+  char *end;
+  unsigned f, m;
+  PyObject *rc = 0;
+  int err;
+
+  if (!PyArg_ParseTuple(arg, "Os:key_readflags", &me, &p))
+    goto end;
+  if ((err = key_readflags(p, &end, &f, &m)) != 0)
+    KEYERR(err);
+  rc = Py_BuildValue("(NNs)", getulong(f), getulong(m), end);
+end:
+  return (rc);
+}
+
+static PyObject *meth__KeyData_writeflags(PyObject *me, PyObject *arg)
+{
+  dstr d = DSTR_INIT;
+  PyObject *rc;
+  unsigned f;
+
+  if (!PyArg_ParseTuple(arg, "OO&:key_writeflags", &me, convuint, &f))
+    return (0);
+  key_writeflags(f, &d);
+  rc = PyString_FromStringAndSize(d.buf, d.len);
+  dstr_destroy(&d);
+  return (rc);
+}
+
+/*----- Key data ----------------------------------------------------------*/
+
+static PyObject *keydata_pywrap(key_data *kd)
+{
+  PyTypeObject *ty;
+  keydata_pyobj *kdobj;
+
+  switch (kd->e & KF_ENCMASK) {
+    case KENC_BINARY: ty = keydatabin_pytype; break;
+    case KENC_ENCRYPT: ty = keydataenc_pytype; break;
+    case KENC_MP: ty = keydatamp_pytype; break;
+    case KENC_STRUCT: ty = keydatastruct_pytype; break;
+    case KENC_STRING: ty = keydatastr_pytype; break;
+    case KENC_EC: ty = keydataec_pytype; break;
+    default: abort();
+  }
+  kdobj = PyObject_NEW(keydata_pyobj, ty);
+  kdobj->kd = kd;
+  return ((PyObject *)kdobj);
+}
+
+static void keydata_pydealloc(PyObject *me)
+{
+  key_drop(KEYDATA_KD(me));
+  FREEOBJ(me);
+}
+
+static PyObject *kdmeth_matchp(PyObject *me, PyObject *arg)
+{
+  key_filter f;
+
+  if (!PyArg_ParseTuple(arg, "O&:matchp", convfilter, &f))
+    return (0);
+  return (getbool(KEY_MATCH(KEYDATA_KD(me), &f)));
+}
+
+static PyObject *kdmeth_split(PyObject *me, PyObject *arg)
+{
+  if (!PyArg_ParseTuple(arg, ":split"))
+    return (0);
+  key_split(&KEYDATA_KD(me));
+  RETURN_ME;
+}
+
+static PyObject *kdmeth_copy(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  key_filter f = { 0, 0 };
+  static char *kwlist[] = { "filter", 0 };
+  key_data *kd;
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:copy", kwlist,
+                                  convfilter, &f))
+    return (0);
+  if ((kd = key_copydata(KEYDATA_KD(me), &f)) == 0)
+    RETURN_NONE;
+  else
+    return (keydata_pywrap(kd));
+}
+
+static PyObject *kdmeth_write(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  key_filter f = { 0, 0 };
+  dstr d = DSTR_INIT;
+  PyObject *rc = 0;
+  static char *kwlist[] = { "filter", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:write", kwlist,
+                                  convfilter, &f))
+    return (0);
+  key_write(KEYDATA_KD(me), &d, &f);
+  rc = PyString_FromStringAndSize(d.buf, d.len);
+  dstr_destroy(&d);
+  return (rc);
+}
+
+static PyObject *kdmeth_encode(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  key_filter f = { 0, 0 };
+  dstr d = DSTR_INIT;
+  PyObject *rc = 0;
+  static char *kwlist[] = { "filter", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O&:encode", kwlist,
+                                  convfilter, &f))
+    return (0);
+  key_encode(KEYDATA_KD(me), &d, &f);
+  rc = bytestring_pywrap(d.buf, d.len);
+  dstr_destroy(&d);
+  return (rc);
+}
+
+static PyObject *kdmeth_plock(PyObject *me, PyObject *arg)
+{
+  char *tag;
+  int err;
+  PyObject *rc = 0;
+  key_data *kd;
+
+  if (!PyArg_ParseTuple(arg, "s:plock", &tag))
+    goto end;
+  if ((err = key_plock(&kd, KEYDATA_KD(me), tag)) != 0)
+    KEYERR(err);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+static PyObject *kdmeth_lock(PyObject *me, PyObject *arg)
+{
+  char *p;
+  Py_ssize_t n;
+  PyObject *rc = 0;
+  key_data *kd;
+
+  if (!PyArg_ParseTuple(arg, "s#:lock", &p, &n))
+    goto end;
+  key_lock(&kd, KEYDATA_KD(me), p, n);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+static PyObject *meth__KeyData_read(PyObject *me, PyObject *arg)
+{
+  const char *p;
+  char *end;
+  key_data *kd;
+  PyObject *rc = 0;
+
+  if (!PyArg_ParseTuple(arg, "Os:read", &me, &p))
+    goto end;
+  if ((kd = key_read(p, &end)) == 0)
+    KEYERR(KERR_MALFORMED);
+  rc = Py_BuildValue("(Ns)", keydata_pywrap(kd), end);
+end:
+  return (rc);
+}
+
+static PyObject *meth__KeyData_decode(PyObject *me, PyObject *arg)
+{
+  const char *p;
+  Py_ssize_t n;
+  key_data *kd;
+  PyObject *rc = 0;
+
+  if (!PyArg_ParseTuple(arg, "Os#:decode", &me, &p, &n))
+    goto end;
+  if ((kd = key_decode(p, n)) == 0)
+    KEYERR(KERR_MALFORMED);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+static PyObject *kdget_flags(PyObject *me, void *hunoz)
+  { return (getulong(KEYDATA_KD(me)->e)); }
+
+static PyMethodDef keydata_pymethods[] = {
+#define METHNAME(func) kdmeth_##func
+  METH (matchp,                "KD.matchp(FILTER) -> BOOL")
+  METH (split,                 "KD.split()")
+  KWMETH(write,                        "KD.write(filter = <any>) -> STRING")
+  KWMETH(encode,               "KD.encode(filter = <any>) -> BYTES")
+  KWMETH(copy,                 "KD.copy(filter = <any>) -> KD")
+  METH (plock,                 "KD.plock(TAG) -> ENCRYPTED-KD")
+  METH (lock,                  "KD.lock(KEY) -> ENCRYPTED-KD")
+#undef METHNAME
+  { 0 }
+};
+
+static PyGetSetDef keydata_pygetset[] = {
+#define GETSETNAME(op, name) kd##op##_##name
+  GET  (flags,                 "KD.flags -> FLAGS")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydata_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyData",                           /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  keydata_pydealloc,                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Key data base class.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  keydata_pymethods,                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydata_pygetset,                    /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  abstract_pynew,                      /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydatabin_pynew(PyTypeObject *ty,
+                                 PyObject *arg, PyObject *kw)
+{
+  char *p;
+  Py_ssize_t n;
+  unsigned f = 0;
+  keydata_pyobj *me = 0;
+  static char *kwlist[] = { "key", "flags", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:new", kwlist,
+                                  &p, &n, convflags, &f))
+    goto end;
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = key_newbinary(f & ~KF_ENCMASK, p, n);
+end:
+  return ((PyObject *)me);
+}
+
+static PyObject *kdbget_bin(PyObject *me, void *hunoz)
+  { return (bytestring_pywrap(KEYDATA_KD(me)->u.k.k,
+                             KEYDATA_KD(me)->u.k.sz)); }
+
+static PyGetSetDef keydatabin_pygetset[] = {
+#define GETSETNAME(op, name) kdb##op##_##name
+  GET  (bin,                   "KD.bin -> BYTES")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydatabin_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataBinary",                     /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataBinary(KEY, [flags = 0]): key data for binary keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydatabin_pygetset,                 /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydatabin_pynew,                    /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydataenc_pynew(PyTypeObject *ty,
+                                 PyObject *arg, PyObject *kw)
+{
+  char *p;
+  Py_ssize_t n;
+  unsigned f = 0;
+  keydata_pyobj *me = 0;
+  static char *kwlist[] = { "key", "flags", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "s#|O&:new", kwlist,
+                                  &p, &n, convflags, &f))
+    goto end;
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = key_newencrypted(f & ~KF_ENCMASK, p, n);
+end:
+  return ((PyObject *)me);
+}
+
+static PyObject *kdemeth_plock(PyObject *me, PyObject *arg)
+{
+  char *hunoz;
+  if (!PyArg_ParseTuple(arg, "s:plock", &hunoz)) goto end;
+  KEYERR(KERR_WRONGTYPE);
+end:
+  return (0);
+}
+
+static PyObject *kdemeth_lock(PyObject *me, PyObject *arg)
+{
+  char *hunoz;
+  Py_ssize_t hukairz;
+  if (!PyArg_ParseTuple(arg, "s#:lock", &hunoz, &hukairz)) goto end;
+  KEYERR(KERR_WRONGTYPE);
+end:
+  return (0);
+}
+
+static PyObject *kdemeth_punlock(PyObject *me, PyObject *arg)
+{
+  char *tag;
+  int err;
+  PyObject *rc = 0;
+  key_data *kd;
+
+  if (!PyArg_ParseTuple(arg, "s:punlock", &tag))
+    goto end;
+  if ((err = key_punlock(&kd, KEYDATA_KD(me), tag)) != 0)
+    KEYERR(err);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+static PyObject *kdemeth_unlock(PyObject *me, PyObject *arg)
+{
+  char *p;
+  Py_ssize_t n;
+  int err;
+  PyObject *rc = 0;
+  key_data *kd;
+
+  if (!PyArg_ParseTuple(arg, "s#:unlock", &p, &n))
+    goto end;
+  if ((err = key_unlock(&kd, KEYDATA_KD(me), p, n)) != 0)
+    KEYERR(err);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+#define kdeget_ct kdbget_bin
+
+static PyMethodDef keydataenc_pymethods[] = {
+#define METHNAME(func) kdemeth_##func
+  METH (plock,                 "KD.plock(TAG) -> ENCRYPTED-KD")
+  METH (lock,                  "KD.lock(KEY) -> ENCRYPTED-KD")
+  METH (punlock,               "KD.punlock(TAG) -> KD")
+  METH (unlock,                "KD.unlock(KEY) -> KD")
+#undef METHNAME
+  { 0 }
+};
+
+static PyGetSetDef keydataenc_pygetset[] = {
+#define GETSETNAME(op, name) kde##op##_##name
+  GET  (ct,                    "KD.ct -> BYTES")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydataenc_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataEncrypted",                  /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataEncrypted(KEY, [flags = 0]): key data for encrypted keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  keydataenc_pymethods,                        /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydataenc_pygetset,                 /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydataenc_pynew,                    /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydatamp_pynew(PyTypeObject *ty,
+                                PyObject *arg, PyObject *kw)
+{
+  mp *x = 0;
+  unsigned f = 0;
+  keydata_pyobj *me = 0;
+  static char *kwlist[] = { "key", "flags", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O&:new", kwlist,
+                                  convmp, &x, convflags, &f))
+    goto end;
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = key_newmp(f & ~KF_ENCMASK, x);
+end:
+  mp_drop(x);
+  return ((PyObject *)me);
+}
+
+static PyObject *kdmget_mp(PyObject *me, void *hunoz)
+  { return (mp_pywrap(MP_COPY(KEYDATA_KD(me)->u.m))); }
+
+static PyGetSetDef keydatamp_pygetset[] = {
+#define GETSETNAME(op, name) kdm##op##_##name
+  GET  (mp,                    "KD.mp -> X")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydatamp_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataMP",                         /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataMP(KEY, [flags = 0]): key data for large-integer keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydatamp_pygetset,                  /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydatamp_pynew,                     /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydatastr_pynew(PyTypeObject *ty,
+                                 PyObject *arg, PyObject *kw)
+{
+  char *p;
+  unsigned f = 0;
+  keydata_pyobj *me = 0;
+  static char *kwlist[] = { "key", "flags", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "s|O&:new", kwlist,
+                                  &p, convflags, &f))
+    goto end;
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = key_newstring(f & ~KF_ENCMASK, p);
+end:
+  return ((PyObject *)me);
+}
+
+static PyObject *kdsget_str(PyObject *me, void *hunoz)
+  { return (PyString_FromString(KEYDATA_KD(me)->u.p)); }
+
+static PyGetSetDef keydatastr_pygetset[] = {
+#define GETSETNAME(op, name) kds##op##_##name
+  GET  (str,                   "KD.str -> STRING")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydatastr_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataString",                     /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataString(KEY, [flags = 0]): key data for string keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydatastr_pygetset,                 /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydatastr_pynew,                    /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydataec_pynew(PyTypeObject *ty,
+                                PyObject *arg, PyObject *kw)
+{
+  ec x = EC_INIT;
+  unsigned f = 0;
+  keydata_pyobj *me = 0;
+  static char *kwlist[] = { "key", "flags", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O&:new", kwlist,
+                                  convecpt, &x, convflags, &f))
+    goto end;
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = key_newec(f & ~KF_ENCMASK, &x);
+end:
+  EC_DESTROY(&x);
+  return ((PyObject *)me);
+}
+
+static PyObject *kdeget_ecpt(PyObject *me, void *hunoz)
+{
+  ec pt = EC_INIT;
+  EC_COPY(&pt, &KEYDATA_KD(me)->u.e);
+  return (ecpt_pywrapout(ecpt_pytype, &pt));
+}
+
+static PyGetSetDef keydataec_pygetset[] = {
+#define GETSETNAME(op, name) kde##op##_##name
+  GET  (ecpt,                  "KD.ecpt -> ECPT")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject keydataec_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataECPt",                       /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataECPt(KEY, [flags = 0]): key data for elliptic-curve keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keydataec_pygetset,                  /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydataec_pynew,                     /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *subkeyiter_make(PyObject *kdobj)
+{
+  subkeyiter_pyobj *me = PyObject_NEW(subkeyiter_pyobj, subkeyiter_pytype);
+  me->kdobj = kdobj;
+  Py_INCREF(kdobj);
+  key_mksubkeyiter(&me->i, KEYDATA_KD(kdobj));
+  return ((PyObject *)me);
+}
+
+static PyObject *subkeyiter_pynext(PyObject *me)
+{
+  const char *tag;
+  if (!key_nextsubkey(SUBKEYITER_I(me), &tag, 0))
+    return (0);
+  return (PyString_FromString(tag));
+}
+
+static void subkeyiter_pydealloc(PyObject *me)
+{
+  Py_DECREF(SUBKEYITER_KDOBJ(me));
+  FREEOBJ(me);
+}
+
+static PyTypeObject subkeyiter_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "SubKeyIter",                                /* @tp_name@ */
+  sizeof(subkeyiter_pyobj),            /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  subkeyiter_pydealloc,                        /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Iterator for structured keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  PyObject_SelfIter,                   /* @tp_iter@ */
+  subkeyiter_pynext,                   /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  0,                                   /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  abstract_pynew,                      /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keydatastruct_pynew(PyTypeObject *ty,
+                                    PyObject *arg, PyObject *kw)
+{
+  PyObject *sub = 0;
+  PyObject *it = 0, *name = 0, *val = 0;
+  char *p;
+  keydata_pyobj *me = 0;
+  key_data *kd = 0;
+  static char *kwlist[] = { "subkeys", 0 };
+
+  Py_XINCREF(arg); Py_XINCREF(kw);
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "|O:new", kwlist, &sub))
+    goto end;
+  kd = key_newstruct();
+  if (sub) {
+    if (!PyMapping_Check(sub))
+      TYERR("subkeys must be an iterable mapping");
+    if ((it = PyObject_GetIter(sub)) == 0)
+      goto end;
+    while ((name = PyIter_Next(it)) != 0) {
+      if ((p = PyString_AsString(name)) == 0 ||
+         (val = PyObject_GetItem(sub, name)) == 0)
+       goto end;
+      if (!KEYDATA_PYCHECK(val))
+       TYERR("subkey objects must be subclasses of KeyData");
+      key_structset(kd, p, KEYDATA_KD(val));
+      Py_DECREF(name); name = 0;
+      Py_DECREF(val); val = 0;
+    }
+    if (PyErr_Occurred())
+      goto end;
+    Py_DECREF(it); it = 0;
+  }
+  me = (keydata_pyobj *)ty->tp_alloc(ty, 0);
+  me->kd = kd;
+end:
+  if (kd && !me) key_drop(kd);
+  Py_XDECREF(name); Py_XDECREF(val); Py_XDECREF(it);
+  Py_XDECREF(arg); Py_XDECREF(kw);
+  return ((PyObject *)me);
+}
+
+static PyObject *keydatastruct_pylookup(PyObject *me, PyObject *key)
+{
+  const char *tag;
+  key_data *kd;
+  PyObject *rc = 0;
+
+  if ((tag = PyString_AsString(key)) == 0)
+    goto end;
+  if ((kd = key_structfind(KEYDATA_KD(me), tag)) == 0)
+    INDEXERR(key);
+  key_incref(kd);
+  rc = keydata_pywrap(kd);
+end:
+  return (rc);
+}
+
+static int keydatastruct_pystore(PyObject *me,
+                                PyObject *key, PyObject *value)
+{
+  const char *tag;
+  int rc = -1;
+
+  if ((tag = PyString_AsString(key)) == 0)
+    goto end;
+  key_split(&KEYDATA_KD(me));
+  if (value) {
+    if (!KEYDATA_PYCHECK(value))
+      TYERR("expected KeyData value");
+    key_structset(KEYDATA_KD(me), tag, KEYDATA_KD(value));
+  } else {
+    if (!key_structfind(KEYDATA_KD(me), tag))
+      INDEXERR(key);
+    key_structset(KEYDATA_KD(me), tag, 0);
+  }
+  rc = 0;
+end:
+  return (rc);
+}
+
+static PyMappingMethods keydatastruct_pymapping = {
+  gmap_pysize,                         /* @mp_length@ */
+  keydatastruct_pylookup,              /* @mp_subscript@ */
+  keydatastruct_pystore                        /* @mp_ass_subscript@ */
+};
+
+static PyTypeObject keydatastruct_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyDataStructured",                 /* @tp_name@ */
+  sizeof(keydata_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  0,                                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  &keydatastruct_pymapping,            /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyDataStructured([subkeys = []]): key data for structured keys.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  subkeyiter_make,                     /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  gmap_pymethods,                      /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  0,                                   /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keydatastruct_pynew,                 /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+/*----- Key attributes ----------------------------------------------------*/
+
+static PyObject *keyattriter_make(PyObject *kaobj)
+{
+  PyObject *kobj = KEYATTRS_KOBJ(kaobj);
+  keyattriter_pyobj *me = PyObject_NEW(keyattriter_pyobj,
+                                      keyattriter_pytype);
+  me->kobj = kobj;
+  Py_INCREF(kobj);
+  key_mkattriter(&me->i, KEY_K(kobj));
+  return ((PyObject *)me);
+}
+
+static PyObject *keyattriter_pynext(PyObject *me)
+{
+  const char *name;
+
+  if (!key_nextattr(KEYATTRITER_I(me), &name, 0))
+    return (0);
+  return (PyString_FromString(name));
+}
+
+static void keyattriter_pydealloc(PyObject *me)
+{
+  Py_DECREF(KEYATTRITER_KOBJ(me));
+  FREEOBJ(me);
+}
+
+static PyTypeObject keyattriter_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyAttributeIter",                  /* @tp_name@ */
+  sizeof(keyattriter_pyobj),           /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  keyattriter_pydealloc,               /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Iterator for key attributes.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  PyObject_SelfIter,                   /* @tp_iter@ */
+  keyattriter_pynext,                  /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  0,                                   /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  abstract_pynew,                      /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+static PyObject *keyattrs_pylookup(PyObject *me, PyObject *key)
+{
+  const char *attr;
+  const char *value;
+  PyObject *rc = 0;
+
+  if ((attr = PyString_AsString(key)) == 0)
+    goto end;
+  if ((value = key_getattr(KEYATTRS_KF(me), KEYATTRS_K(me), attr)) == 0)
+    INDEXERR(key);
+  rc = PyString_FromString(value);
+end:
+  return (rc);
+}
+
+static int keyattrs_pystore(PyObject *me,
+                           PyObject *key, PyObject *value)
+{
+  const char *attr;
+  const char *val;
+  int err;
+  int rc = -1;
+
+  if ((attr = PyString_AsString(key)) == 0)
+    goto end;
+  if (value) {
+    if ((val = PyString_AsString(value)) == 0)
+      goto end;
+    if ((err = key_putattr(KEYATTRS_KF(me), KEYATTRS_K(me),
+                          attr, val)) != 0)
+      KEYERR(err);
+  } else {
+    if (!key_getattr(KEYATTRS_KF(me), KEYATTRS_K(me), attr))
+      INDEXERR(key);
+    if ((err = key_putattr(KEYATTRS_KF(me), KEYATTRS_K(me), attr, 0)) != 0)
+      KEYERR(err);
+  }
+  rc = 0;
+end:
+  return (rc);
+}
+
+static PyObject *keyattrs_make(PyObject *kobj)
+{
+  keyattrs_pyobj *me = PyObject_NEW(keyattrs_pyobj, keyattrs_pytype);
+  me->kobj = kobj;
+  Py_INCREF(kobj);
+  return ((PyObject *)me);
+}
+
+static void keyattrs_pydealloc(PyObject *me)
+{
+  Py_DECREF(KEYATTRS_KOBJ(me));
+  FREEOBJ(me);
+}
+
+static PyMappingMethods keyattrs_pymapping = {
+  gmap_pysize,                         /* @mp_length@ */
+  keyattrs_pylookup,                   /* @mp_subscript@ */
+  keyattrs_pystore                     /* @mp_ass_subscript@ */
+};
+
+static PyTypeObject keyattrs_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyAttributes",                     /* @tp_name@ */
+  sizeof(keyattrs_pyobj),              /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  keyattrs_pydealloc,                  /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  &gmap_pysequence,                    /* @tp_as_sequence@ */
+  &keyattrs_pymapping,                 /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Proxy thing for talking about key attributes.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  keyattriter_make,                    /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  gmap_pymethods,                      /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  0,                                   /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  abstract_pynew,                      /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+/*----- Key objects -------------------------------------------------------*/
+
+static PyObject *key_dowrap(PyTypeObject *ty, PyObject *kfobj, key *k)
+{
+  key_pyobj *kobj = (key_pyobj *)ty->tp_alloc(ty, 0);
+  kobj->kfobj = kfobj;
+  Py_INCREF(kfobj);
+  kobj->k = k;
+  return ((PyObject *)kobj);
+}
+
+static PyObject *key_pywrap(PyObject *kfobj, key *k)
+  { return (key_dowrap(key_pytype, kfobj, k)); }
+
+static PyObject *key_pynew(PyTypeObject *ty, PyObject *arg, PyObject *kw)
+{
+  PyObject *kfobj;
+  uint32 id;
+  char *type;
+  unsigned long exptime = KEXP_FOREVER;
+  static char *kwlist[] = { "keyfile", "id", "type", "exptime", 0 };
+  key *k;
+  int err;
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!O&s|O&:new", kwlist,
+                                  keyfile_pytype, &kfobj, convu32, &id,
+                                  &type, convulong, &exptime))
+    goto end;
+  if ((err = key_new(KEYFILE_KF(kfobj), id, type, exptime, &k)) != 0)
+    KEYERR(err);
+  return (key_dowrap(ty, kfobj, k));
+end:
+  return (0);
+}
+
+static void key_pydealloc(PyObject *me)
+{
+  Py_DECREF(KEY_KFOBJ(me));
+  FREEOBJ(me);
+}
+
+static PyObject *kmeth_delete(PyObject *me, PyObject *arg)
+{
+  int err;
+
+  if (!PyArg_ParseTuple(arg, ":delete")) goto end;
+  if ((err = key_delete(KEY_KF(me), KEY_K(me))) != 0) KEYERR(err);
+  RETURN_ME;
+end:
+  return (0);
+}
+
+static PyObject *kmeth_expire(PyObject *me, PyObject *arg)
+{
+  int err;
+
+  if (!PyArg_ParseTuple(arg, ":expire")) goto end;
+  if ((err = key_expire(KEY_KF(me), KEY_K(me))) != 0) KEYERR(err);
+  RETURN_ME;
+end:
+  return (0);
+}
+
+static PyObject *kmeth_used(PyObject *me, PyObject *arg)
+{
+  long t;
+  int err;
+
+  if (!PyArg_ParseTuple(arg, "l:used", &t)) goto end;
+  if ((err = key_used(KEY_KF(me), KEY_K(me), t)) != 0) KEYERR(err);
+  RETURN_ME;
+end:
+  return (0);
+}
+
+static PyObject *kmeth_extract(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  key_filter f = { 0, 0 };
+  PyObject *file;
+  PyObject *nameobj;
+  char *name;
+  FILE *fp;
+  static char *kwlist[] = { "file", "filter", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!|O&:extract", kwlist,
+                                  &PyFile_Type, &file,
+                                  convfilter, &f) ||
+      (fp = PyFile_AsFile(file)) == 0 ||
+      (nameobj = PyFile_Name(file)) == 0 ||
+      (name = PyString_AsString(nameobj)) == 0)
+    goto end;
+  if (key_extract(KEY_KF(me), KEY_K(me), fp, &f))
+    OSERR(name);
+  RETURN_ME;
+end:
+  return (0);
+}
+
+static PyObject *kmeth_fingerprint(PyObject *me,
+                                  PyObject *arg, PyObject *kw)
+{
+  ghash *h;
+  key_filter f = { KF_NONSECRET, KF_NONSECRET };
+  static char *kwlist[] = { "hash", "filter", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&|O&:fingerprint", kwlist,
+                                  convghash, &h, convfilter, &f))
+    return (0);
+  return (getbool(key_fingerprint(KEY_K(me), h, &f)));
+}
+
+static PyObject *kget_id(PyObject *me, void *hunoz)
+  { return (getulong(KEY_K(me)->id)); }
+static PyObject *kget_file(PyObject *me, void *hunoz)
+  { RETURN_OBJ(KEY_KFOBJ(me)); }
+static PyObject *kget_type(PyObject *me, void *hunoz)
+  { return (PyString_FromString(KEY_K(me)->type)); }
+static PyObject *kget_exptime(PyObject *me, void *hunoz)
+  { return (getulong(KEY_K(me)->exp)); }
+static PyObject *kget_deltime(PyObject *me, void *hunoz)
+  { return (getulong(KEY_K(me)->del)); }
+static PyObject *kget_expiredp(PyObject *me, void *hunoz)
+  { return (getbool(key_expired(KEY_K(me)))); }
+static PyObject *kget_attr(PyObject *me, void *hunoz)
+  { return (keyattrs_make(me)); }
+
+static int kset_exptime(PyObject *me, PyObject *x, void *hunoz)
+{
+  key *k = KEY_K(me);
+  unsigned long et;
+
+  if (!convulong(x, &et))
+    goto end;
+  if (!(KEY_KF(me)->f & KF_WRITE))
+    KEYERR(KERR_READONLY);
+  k->exp = et;
+  KEY_KF(me)->f |= KF_MODIFIED;
+  return (0);
+end:
+  return (-1);
+}
+
+static int kset_deltime(PyObject *me, PyObject *x, void *hunoz)
+{
+  key *k = KEY_K(me);
+  unsigned long dt;
+
+  if (!convulong(x, &dt))
+    goto end;
+  if (dt == KEXP_FOREVER && k->exp != KEXP_FOREVER)
+    VALERR("key will eventually expire");
+  if (!(KEY_KF(me)->f & KF_WRITE))
+    KEYERR(KERR_READONLY);
+  k->del = dt;
+  KEY_KF(me)->f |= KF_MODIFIED;
+  return (0);
+end:
+  return (-1);
+}
+
+static PyObject *kget_data(PyObject *me, void *hunoz)
+{
+  key_data *kd = KEY_K(me)->k;
+  key_incref(kd);
+  return (keydata_pywrap(kd));
+}
+static int kset_data(PyObject *me, PyObject *x, void *hunoz)
+{
+  int err;
+
+  if (!x) NIERR("__del__");
+  if (!KEYDATA_PYCHECK(x)) TYERR("expected KeyData object");
+  if ((err = key_setkeydata(KEY_KF(me), KEY_K(me), KEYDATA_KD(x))) != 0)
+    KEYERR(err);
+  return (0);
+end:
+  return (-1);
+}
+
+static PyObject *kget_fulltag(PyObject *me, void *hunoz)
+{
+  dstr d = DSTR_INIT;
+  PyObject *rc;
+
+  key_fulltag(KEY_K(me), &d);
+  rc = PyString_FromStringAndSize(d.buf, d.len);
+  dstr_destroy(&d);
+  return (rc);
+}
+
+static PyObject *kget_tag(PyObject *me, void *hunoz)
+{
+  if (!KEY_K(me)->tag) RETURN_NONE;
+  return (PyString_FromString(KEY_K(me)->tag));
+}
+static int kset_tag(PyObject *me, PyObject *x, void *hunoz)
+{
+  int err;
+  char *tag;
+
+  if (!x || x == Py_None) tag = 0;
+  else if ((tag = PyString_AsString(x)) == 0) goto end;
+  if ((err = key_settag(KEY_KF(me), KEY_K(me), tag)) != 0) KEYERR(err);
+  return (0);
+end:
+  return (-1);
+}
+
+static PyObject *kget_comment(PyObject *me, void *hunoz)
+{
+  if (!KEY_K(me)->c) RETURN_NONE;
+  return (PyString_FromString(KEY_K(me)->c));
+}
+static int kset_comment(PyObject *me, PyObject *x, void *hunoz)
+{
+  int err;
+  char *c;
+
+  if (!x || x == Py_None) c = 0;
+  else if ((c = PyString_AsString(x)) == 0) goto end;
+  if ((err = key_setcomment(KEY_KF(me), KEY_K(me), c)) != 0) KEYERR(err);
+  return (0);
+end:
+  return (-1);
+}
+
+static PyMethodDef key_pymethods[] = {
+#define METHNAME(func) kmeth_##func
+  METH (delete,        "KEY.delete()")
+  METH (expire,        "KEY.expire()")
+  METH (used,          "KEY.used(TIME)")
+  KWMETH(extract,      "KEY.extract(FILE, filter = '')")
+  KWMETH(fingerprint,  "KEY.fingerprint(HASH, filtr = '-secret')")
+#undef METHNAME
+  { 0 }
+};
+
+static PyGetSetDef key_pygetset[] = {
+#define GETSETNAME(op, name) k##op##_##name
+  GET  (file,          "KEY.file -> KF")
+  GET  (id,            "KEY.id -> ID")
+  GETSET(tag,          "KEY.tag -> TAG")
+  GET  (type,          "KEY.type -> TYPE")
+  GETSET(exptime,      "KEY.exptime -> TIME")
+  GETSET(deltime,      "KEY.deltime -> TIME")
+  GET  (expiredp,      "KEY.expiredp -> BOOL")
+  GET  (attr,          "KEY.attr -> ATTRIBUTES")
+  GETSET(data,         "KEY.data -> KD")
+  GETSET(comment,      "KEY.comment -> COMMENT")
+  GET  (fulltag,       "KEY.fulltag -> FULLTAG")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyTypeObject key_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "Key",                               /* @tp_name@ */
+  sizeof(key_pyobj),                   /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  key_pydealloc,                       /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Key(KF, ID, TYPE, [exptime = KEXP_FOREVER]): key object.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  0,                                   /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  key_pymethods,                       /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  key_pygetset,                                /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  key_pynew,                           /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+/*----- Key iteration -----------------------------------------------------*/
+
+static PyObject *keyiter_new(PyObject *kfobj)
+{
+  keyiter_pyobj *me = PyObject_NEW(keyiter_pyobj, keyiter_pytype);
+  key_mkiter(&me->i, KEYFILE_KF(kfobj));
+  me->kfobj = kfobj;
+  Py_INCREF(kfobj);
+  return ((PyObject *)me);
+}
+
+static PyObject *keyiter_pynext(PyObject *me)
+{
+  key *k;
+
+  if ((k = key_next(KEYITER_I(me))) == 0)
+    return (0);
+  return (getulong(k->id));
+}
+
+static void keyiter_pydealloc(PyObject *me)
+{
+  Py_DECREF(KEYITER_KFOBJ(me));
+  FREEOBJ(me);
+}
+
+static PyTypeObject keyiter_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyFileIter",                       /* @tp_name@ */
+  sizeof(keyiter_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  keyiter_pydealloc,                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  0,                                   /* @tp_as_sequence@ */
+  0,                                   /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"Keyring iterator.",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  PyObject_SelfIter,                   /* @tp_iter@ */
+  keyiter_pynext,                      /* @tp_iternext@ */
+  0,                                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  0,                                   /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  abstract_pynew,                      /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
 /*----- Key files ---------------------------------------------------------*/
 
+struct reportinfo {
+  PyObject *func;
+  int stop;
+};
+
+static void pythonreporter(const char *file, int line,
+                          const char *msg, void *p)
+{
+  struct reportinfo *ri = p;
+  PyObject *res = 0;
+
+  if (ri->stop)
+    return;
+  if (!ri->func)
+    key_moan(file, line, msg, 0);
+  else if ((res = PyObject_CallFunction(ri->func, "sis",
+                                       file, line, msg)) == 0)
+    ri->stop = 1;
+  else
+    Py_DECREF(res);
+}
+
 static PyObject *keyfile_pynew(PyTypeObject *ty,
                               PyObject *arg, PyObject *kw)
 {
-  
+  struct reportinfo ri = { 0, 0 };
+  char *file = 0;
+  unsigned how = KOPEN_READ;
+  keyfile_pyobj *rc = 0;
+  static char *kwlist[] = { "file", "how", "report", 0 };
+
+  Py_XINCREF(arg); Py_XINCREF(kw);
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "s|iO:new", kwlist,
+                                  &file, &how, &ri.func))
+    goto end;
+  if (ri.func && !PyCallable_Check(ri.func))
+    TYERR("reporter function not callable");
+  if ((rc = (keyfile_pyobj *)ty->tp_alloc(ty, 0)) == 0)
+    goto end;
+  if (key_open(&rc->kf, file, how, pythonreporter, &ri))
+    OSERR(file);
+  if (ri.stop) {
+    key_discard(&rc->kf);
+    goto end;
+  }
+  goto done;
+
+end:
+  if (rc) {
+    FREEOBJ(rc);
+    rc = 0;
+  }
+done:
+  Py_XDECREF(arg); Py_XDECREF(kw);
+  return ((PyObject *)rc);
+}
+
+static void keyfile_pydealloc(PyObject *me)
+{
+  key_discard(KEYFILE_KF(me));
+  FREEOBJ(me);
+}
+
+static PyObject *kfmeth_save(PyObject *me, PyObject *arg)
+{
+  if (!PyArg_ParseTuple(arg, ":save"))
+    goto end;
+  switch (key_save(KEYFILE_KF(me))) {
+    case KWRITE_OK:
+      RETURN_ME;
+    case KWRITE_FAIL:
+      KEYIOERR(KEYFILE_KF(me)->name);
+    case KWRITE_BROKEN:
+      KEYFILEBROKEN(KEYFILE_KF(me)->name);
+    default:
+      abort();
+  }
+end:
+  return (0);
+}
+
+static PyObject *kfmeth_merge(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  struct reportinfo ri = { 0, 0 };
+  char *name;
+  PyObject *x = 0;
+  FILE *fp = 0;
+  int rc;
+  static char *kwlist[] = { "file", "report", 0 };
+
+  Py_XINCREF(arg); Py_XINCREF(kw);
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O!|O:merge", kwlist,
+                                  &PyFile_Type, &x, &ri.func))
+    goto end;
+  if (ri.func && !PyCallable_Check(ri.func))
+    TYERR("reporter function not callable");
+  if ((fp = PyFile_AsFile(x)) == 0)
+    goto end;
+  x = PyFile_Name(x);
+  if ((name = PyString_AsString(x)) == 0)
+    goto end;
+  rc = key_merge(KEYFILE_KF(me), name, fp, pythonreporter, &ri);
+  if (ri.stop)
+    goto end;
+  if (rc != 0)
+    KEYERR(rc);
+  Py_XDECREF(arg); Py_XDECREF(kw);
+  RETURN_ME;
+
+end:
+  Py_XDECREF(arg); Py_XDECREF(kw);
+  return (0);
+}
+
+static PyObject *kfmeth_byid(PyObject *me, PyObject *arg)
+{
+  uint32 id;
+  key *k;
+  PyObject *rc = 0;
+
+  if (!PyArg_ParseTuple(arg, "O&:byid", convu32, &id)) goto end;
+  if ((k = key_byid(KEYFILE_KF(me), id)) == 0) KEYERR(KERR_NOTFOUND);
+  rc = key_pywrap(me, k);
+end:
+  return (rc);
+}
+
+static PyObject *kfmeth_bytype(PyObject *me, PyObject *arg)
+{
+  char *type;
+  key *k;
+  PyObject *rc = 0;
+
+  if (!PyArg_ParseTuple(arg, "s:bytype", &type)) goto end;
+  if ((k = key_bytype(KEYFILE_KF(me), type)) == 0) RETURN_NONE;
+  rc = key_pywrap(me, k);
+end:
+  return (rc);
+}
+
+static PyObject *bytag(PyObject *me, PyObject *tagobj)
+{
+  uint32 id;
+  char *tag;
+  key *k;
+  PyObject *rc = 0;
+
+  if (convu32(tagobj, &id))
+    k = key_byid(KEYFILE_KF(me), id);
+  else {
+    PyErr_Clear();
+    if ((tag = PyString_AsString(tagobj)) == 0)
+      goto end;
+    k = key_bytag(KEYFILE_KF(me), tag);
+  }
+  if (!k) RETURN_NONE;
+  rc = key_pywrap(me, k);
+end:
+  return (rc);
+}
+
+static PyObject *kfmeth_bytag(PyObject *me, PyObject *arg)
+{
+  PyObject *tagobj;
+
+  if (!PyArg_ParseTuple(arg, "O:bytag", &tagobj)) return (0);
+  return (bytag(me, tagobj));
+}
+
+static PyObject *keyfile_pylookup(PyObject *me, PyObject *key)
+{
+  PyObject *rc = bytag(me, key);
+  if (!rc) goto end;
+  if (rc == Py_None) {
+    Py_DECREF(rc);
+    rc = 0;
+    INDEXERR(key);
+  }
+end:
+  return (rc);
+}
+
+static PyObject *kfmeth_newkey(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  uint32 id;
+  char *type;
+  long exptime = KEXP_FOREVER;
+  static char *kwlist[] = { "id", "type", "exptime", 0 };
+  key *k;
+  int err;
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "O&s|l:newkey", kwlist,
+                                  convu32, &id, &type, &exptime))
+    goto end;
+  if ((err = key_new(KEYFILE_KF(me), id, type, exptime, &k)) != 0)
+    KEYERR(err);
+  return (key_pywrap(me, k));
+end:
+  return (0);
+}
+
+static PyObject *kfmeth_qtag(PyObject *me, PyObject *arg, PyObject *kw)
+{
+  key *k;
+  key_data **kd, *okd;
+  PyObject *newkdobj = 0;
+  char *tag;
+  dstr d = DSTR_INIT;
+  PyObject *rc = 0;
+  static char *kwlist[] = { "tag", "new", 0 };
+
+  if (!PyArg_ParseTupleAndKeywords(arg, kw, "s|O!:qtag", kwlist,
+                                  &tag, keydata_pytype, &newkdobj))
+    goto end;
+  if (key_qtag(KEYFILE_KF(me), tag, &d, &k, &kd))
+    KEYERR(KERR_NOTFOUND);
+  okd = *kd;
+  if (newkdobj) {
+    if (!(KEYFILE_KF(me)->f & KF_WRITE))
+      KEYERR(KERR_READONLY);
+    KEYFILE_KF(me)->f |= KF_MODIFIED;
+    *kd = KEYDATA_KD(newkdobj);
+  }
+  key_incref(*kd);
+  rc = Py_BuildValue("(s#NN)",
+                    d.buf, (Py_ssize_t)d.len,
+                    key_pywrap(me, k),
+                    keydata_pywrap(okd));
+end:
+  return (rc);
+}
+
+static PyObject *kfget_name(PyObject *me, void *hunoz)
+  { return (PyString_FromString(KEYFILE_KF(me)->name)); }
+static PyObject *kfget_modifiedp(PyObject *me, void *hunoz)
+  { return (getbool(KEYFILE_KF(me)->f & KF_MODIFIED)); }
+static PyObject *kfget_writep(PyObject *me, void *hunoz)
+  { return (getbool(KEYFILE_KF(me)->f & KF_WRITE)); }
+static PyObject *kfget_filep(PyObject *me, void *hunoz)
+  { return (getbool(!!KEYFILE_KF(me)->fp)); }
+
+static PyMethodDef keyfile_pymethods[] = {
+#define METHNAME(func) kfmeth_##func
+  METH (save,          "KF.save()")
+  KWMETH(merge,                "KF.merge(FILE, report = <built-in-reporter>)")
+  KWMETH(newkey,       "KF.newkey(ID, TYPE, exptime = KEXP_FOREVER) -> KEY")
+  METH (byid,          "KF.byid(KEYID) -> KEY|None")
+  METH (bytype,        "KF.bytype(TYPE) -> KEY|None")
+  METH (bytag,         "KF.bytag(TAG) -> KEY|None")
+  KWMETH(qtag,         "KF.qtag(TAG, new = KD) -> FULLTAG, KEY, OLDKD")
+  GMAP_ROMETHODS
+#undef METHNAME
+  { 0 }
+};
+
+static PyGetSetDef keyfile_pygetset[] = {
+#define GETSETNAME(op, name) kf##op##_##name
+  GET  (name,          "KF.name -> file name")
+  GET  (modifiedp,     "KF.modifiedp -> has keyring been modified?")
+  GET  (writep,        "KF.writep -> is keyring modifiable?")
+  GET  (filep,         "KF.filep -> does keyring have a backing file?")
+#undef GETSETNAME
+  { 0 }
+};
+
+static PyMappingMethods keyfile_pymapping = {
+  gmap_pysize,
+  keyfile_pylookup,
+  0
+};
+
+static PyTypeObject keyfile_pytype_skel = {
+  PyObject_HEAD_INIT(0) 0,             /* Header */
+  "KeyFile",                           /* @tp_name@ */
+  sizeof(keyfile_pyobj),               /* @tp_basicsize@ */
+  0,                                   /* @tp_itemsize@ */
+
+  keyfile_pydealloc,                   /* @tp_dealloc@ */
+  0,                                   /* @tp_print@ */
+  0,                                   /* @tp_getattr@ */
+  0,                                   /* @tp_setattr@ */
+  0,                                   /* @tp_compare@ */
+  0,                                   /* @tp_repr@ */
+  0,                                   /* @tp_as_number@ */
+  &gmap_pysequence,                    /* @tp_as_sequence@ */
+  &keyfile_pymapping,                  /* @tp_as_mapping@ */
+  0,                                   /* @tp_hash@ */
+  0,                                   /* @tp_call@ */
+  0,                                   /* @tp_str@ */
+  0,                                   /* @tp_getattro@ */
+  0,                                   /* @tp_setattro@ */
+  0,                                   /* @tp_as_buffer@ */
+  Py_TPFLAGS_DEFAULT |                 /* @tp_flags@ */
+    Py_TPFLAGS_BASETYPE,
+
+  /* @tp_doc@ */
+"KeyFile(FILE, [how = KOPEN_READ], [report = ?]): Keyring file.\n\
+   calls REPORT(FILE, LINE, MSG) on problems",
+
+  0,                                   /* @tp_traverse@ */
+  0,                                   /* @tp_clear@ */
+  0,                                   /* @tp_richcompare@ */
+  0,                                   /* @tp_weaklistoffset@ */
+  keyiter_new,                         /* @tp_iter@ */
+  0,                                   /* @tp_iternext@ */
+  keyfile_pymethods,                   /* @tp_methods@ */
+  0,                                   /* @tp_members@ */
+  keyfile_pygetset,                    /* @tp_getset@ */
+  0,                                   /* @tp_base@ */
+  0,                                   /* @tp_dict@ */
+  0,                                   /* @tp_descr_get@ */
+  0,                                   /* @tp_descr_set@ */
+  0,                                   /* @tp_dictoffset@ */
+  0,                                   /* @tp_init@ */
+  PyType_GenericAlloc,                 /* @tp_alloc@ */
+  keyfile_pynew,                       /* @tp_new@ */
+  0,                                   /* @tp_free@ */
+  0                                    /* @tp_is_gc@ */
+};
+
+/*----- Global stuff ------------------------------------------------------*/
+
+static PyObject *meth_barf(PyObject *me, PyObject *arg)
+{
+  int err;
+
+  if (PyArg_ParseTuple(arg, "i:barf", &err))
+    KEYERR(err);
+end:
+  return (0);
+}
+
+static PyMethodDef methods[] = {
+#define METHNAME(func) meth_##func
+  METH (_KeyData_readflags,
+          "KeyData.readflags(STRING) -> (FLAGS, MASK, REST)")
+  METH (_KeyData_writeflags,   "KeyData.writeflags(FLAGS) -> STRING")
+  METH (_KeyData_read,         "KeyData.read(STRING) -> (KD, REST)")
+  METH (_KeyData_decode,       "KeyData.decode(BYTES) -> KD")
+  METH (barf,                  "barf(ERR)")
+#undef METHNAME
+  { 0 }
+};
+
+/*----- Initialization ----------------------------------------------------*/
+
+void key_pyinit(void)
+{
+  INITTYPE(keyfile, root);
+  INITTYPE(key, root);
+  INITTYPE(keyiter, root);
+  INITTYPE(keydata, root);
+  INITTYPE(keydatabin, keydata);
+  INITTYPE(keydataenc, keydata);
+  INITTYPE(keydatastr, keydata);
+  INITTYPE(keydatamp, keydata);
+  INITTYPE(keydataec, keydata);
+  INITTYPE(keydatastruct, keydata);
+  INITTYPE(subkeyiter, root);
+  INITTYPE(keyattrs, root);
+  INITTYPE(keyattriter, root);
+  addmethods(methods);
+}
+
+void key_pyinsert(PyObject *mod)
+{
+  INSEXC("KeyError", keyexc, PyExc_Exception, keyexc_pymethods);
+  INSEXC("KeyFileIOError", keyioexc, PyExc_OSError, 0);
+  INSEXC("KeyFileBroken", keyfilebrokenexc, keyioexc, 0);
+  INSERT("KeyFile", keyfile_pytype);
+  INSERT("KeyFileIter", keyiter_pytype);
+  INSERT("Key", key_pytype);
+  INSERT("KeyAttributes", keyattrs_pytype);
+  INSERT("KeyAttributeIter", keyattriter_pytype);
+  INSERT("KeyData", keydata_pytype);
+  INSERT("KeyDataBinary", keydatabin_pytype);
+  INSERT("KeyDataEncrypted", keydataenc_pytype);
+  INSERT("KeyDataMP", keydatamp_pytype);
+  INSERT("KeyDataECPt", keydataec_pytype);
+  INSERT("KeyDataString", keydatastr_pytype);
+  INSERT("KeyDataStructured", keydatastruct_pytype);
+  INSERT("SubKeyIter", subkeyiter_pytype);
 }
 
 /*----- That's all, folks -------------------------------------------------*/