Allow specification of trusted devices by thumbprint rather than
[dcpomatic.git] / src / tools / dcpomatic_kdm_cli.cc
index 4b7a35f7ebf4b144c4f6e08804044998120498cf..3dc3f21b017618ff8b448c47049f6fe7c151a193 100644 (file)
@@ -51,22 +51,24 @@ static void
 help ()
 {
        cerr << "Syntax: " << program_name << " [OPTION] <FILM|CPL-ID|DKDM>\n"
-               "  -h, --help                    show this help\n"
-               "  -o, --output                  output file or directory\n"
-               "  -K, --filename-format         filename format for KDMs\n"
-               "  -Z, --container-name-format   filename format for ZIP containers\n"
-               "  -f, --valid-from              valid from time (in local time zone of the cinema) (e.g. \"2013-09-28 01:41:51\") or \"now\"\n"
-               "  -t, --valid-to                valid to time (in local time zone of the cinema) (e.g. \"2014-09-28 01:41:51\")\n"
-               "  -d, --valid-duration          valid duration (e.g. \"1 day\", \"4 hours\", \"2 weeks\")\n"
-               "  -F, --formulation             modified-transitional-1, multiple-modified-transitional-1, dci-any or dci-specific [default modified-transitional-1]\n"
-               "  -z, --zip                     ZIP each cinema's KDMs into its own file\n"
-               "  -v, --verbose                 be verbose\n"
-               "  -c, --cinema                  specify a cinema, either by name or email address\n"
-               "  -S, --screen                  screen description\n"
-               "  -C, --certificate             file containing projector certificate\n"
-               "  -T, --trusted-device          file containing a trusted device's certificate\n"
-               "      --list-cinemas            list known cinemas from the DCP-o-matic settings\n"
-               "      --list-dkdm-cpls          list CPLs for which DCP-o-matic has DKDMs\n\n"
+               "  -h, --help                               show this help\n"
+               "  -o, --output                             output file or directory\n"
+               "  -K, --filename-format                    filename format for KDMs\n"
+               "  -Z, --container-name-format              filename format for ZIP containers\n"
+               "  -f, --valid-from                         valid from time (in local time zone of the cinema) (e.g. \"2013-09-28 01:41:51\") or \"now\"\n"
+               "  -t, --valid-to                           valid to time (in local time zone of the cinema) (e.g. \"2014-09-28 01:41:51\")\n"
+               "  -d, --valid-duration                     valid duration (e.g. \"1 day\", \"4 hours\", \"2 weeks\")\n"
+               "  -F, --formulation                        modified-transitional-1, multiple-modified-transitional-1, dci-any or dci-specific [default modified-transitional-1]\n"
+               "  -a, --disable-forensic-marking-picture   disable forensic of pictures essences\n"
+               "  -a, --disable-forensic-marking-audio     disable forensic of audio essences (optionally above a given channel, e.g 12)\n"
+               "  -z, --zip                                ZIP each cinema's KDMs into its own file\n"
+               "  -v, --verbose                            be verbose\n"
+               "  -c, --cinema                             specify a cinema, either by name or email address\n"
+               "  -S, --screen                             screen description\n"
+               "  -C, --certificate                        file containing projector certificate\n"
+               "  -T, --trusted-device                     file containing a trusted device's certificate\n"
+               "      --list-cinemas                       list known cinemas from the DCP-o-matic settings\n"
+               "      --list-dkdm-cpls                     list CPLs for which DCP-o-matic has DKDMs\n\n"
                "CPL-ID must be the ID of a CPL that is mentioned in DCP-o-matic's DKDM list.\n\n"
                "For example:\n\n"
                "Create KDMs for my_great_movie to play in all of Fred's Cinema's screens for the next two weeks and zip them up.\n"
@@ -192,6 +194,8 @@ from_film (
        boost::posix_time::ptime valid_from,
        boost::posix_time::ptime valid_to,
        dcp::Formulation formulation,
+       bool disable_forensic_marking_picture,
+       optional<int> disable_forensic_marking_audio,
        bool zip
        )
 {
@@ -224,7 +228,7 @@ from_film (
 
        try {
                list<ScreenKDM> screen_kdms = film->make_kdms (
-                       screens, cpl, valid_from, valid_to, formulation
+                       screens, cpl, valid_from, valid_to, formulation, disable_forensic_marking_picture, disable_forensic_marking_audio
                        );
 
                write_files (screen_kdms, zip, output, container_name_format, filename_format, values, verbose);
@@ -269,10 +273,12 @@ dcp::EncryptedKDM
 kdm_from_dkdm (
        dcp::DecryptedKDM dkdm,
        dcp::Certificate target,
-       vector<dcp::Certificate> trusted_devices,
+       vector<string> trusted_devices,
        dcp::LocalTime valid_from,
        dcp::LocalTime valid_to,
-       dcp::Formulation formulation
+       dcp::Formulation formulation,
+       bool disable_forensic_marking_picture,
+       optional<int> disable_forensic_marking_audio
        )
 {
        /* Signer for new KDM */
@@ -294,7 +300,7 @@ kdm_from_dkdm (
                kdm.add_key(j);
        }
 
-       return kdm.encrypt (signer, target, trusted_devices, formulation);
+       return kdm.encrypt (signer, target, trusted_devices, formulation, disable_forensic_marking_picture, disable_forensic_marking_audio);
 }
 
 void
@@ -308,6 +314,8 @@ from_dkdm (
        boost::posix_time::ptime valid_from,
        boost::posix_time::ptime valid_to,
        dcp::Formulation formulation,
+       bool disable_forensic_marking_picture,
+       optional<int> disable_forensic_marking_audio,
        bool zip
        )
 {
@@ -329,10 +337,12 @@ from_dkdm (
                                        kdm_from_dkdm (
                                                dkdm,
                                                i->recipient.get(),
-                                               i->trusted_devices,
+                                               i->trusted_device_thumbprints(),
                                                dcp::LocalTime(valid_from, i->cinema->utc_offset_hour(), i->cinema->utc_offset_minute()),
                                                dcp::LocalTime(valid_to, i->cinema->utc_offset_hour(), i->cinema->utc_offset_minute()),
-                                               formulation
+                                               formulation,
+                                               disable_forensic_marking_picture,
+                                               disable_forensic_marking_audio
                                                )
                                        )
                                );
@@ -380,7 +390,6 @@ int main (int argc, char* argv[])
        shared_ptr<Cinema> cinema;
        string screen_description = "";
        list<shared_ptr<Screen> > screens;
-       optional<dcp::Certificate> certificate;
        optional<dcp::EncryptedKDM> dkdm;
        optional<boost::posix_time::ptime> valid_from;
        optional<boost::posix_time::ptime> valid_to;
@@ -390,6 +399,8 @@ int main (int argc, char* argv[])
        optional<string> duration_string;
        bool verbose = false;
        dcp::Formulation formulation = dcp::MODIFIED_TRANSITIONAL_1;
+       bool disable_forensic_marking_picture = false;
+       optional<int> disable_forensic_marking_audio;
 
        program_name = argv[0];
 
@@ -404,6 +415,8 @@ int main (int argc, char* argv[])
                        { "valid-to", required_argument, 0, 't'},
                        { "valid-duration", required_argument, 0, 'd'},
                        { "formulation", required_argument, 0, 'F' },
+                       { "disable-forensic-marking-picture", no_argument, 0, 'p' },
+                       { "disable-forensic-marking-audio", optional_argument, 0, 'a' },
                        { "zip", no_argument, 0, 'z' },
                        { "verbose", no_argument, 0, 'v' },
                        { "cinema", required_argument, 0, 'c' },
@@ -415,7 +428,7 @@ int main (int argc, char* argv[])
                        { 0, 0, 0, 0 }
                };
 
-               int c = getopt_long (argc, argv, "ho:K:Z:f:t:d:F:zvc:S:C:T:BD", long_options, &option_index);
+               int c = getopt_long (argc, argv, "ho:K:Z:f:t:d:F:pa::zvc:S:C:T:BD", long_options, &option_index);
 
                if (c == -1) {
                        break;
@@ -456,6 +469,17 @@ int main (int argc, char* argv[])
                                error ("unrecognised KDM formulation " + string (optarg));
                        }
                        break;
+               case 'p':
+                       disable_forensic_marking_picture = true;
+                       break;
+               case 'a':
+                       disable_forensic_marking_audio = 0;
+                       if (optarg == 0 && argv[optind] != 0 && argv[optind][0] != '-') {
+                               disable_forensic_marking_audio = atoi (argv[optind++]);
+                       } else if (optarg) {
+                               disable_forensic_marking_audio = atoi (optarg);
+                       }
+                       break;
                case 'z':
                        zip = true;
                        break;
@@ -463,24 +487,31 @@ int main (int argc, char* argv[])
                        verbose = true;
                        break;
                case 'c':
+                       /* This could be a cinema to search for in the configured list or the name of a cinema being
+                          built up on-the-fly in the option.  Cater for both possilibities here by storing the name
+                          (for lookup) and by creating a Cinema which the next Screen will be added to.
+                       */
                        cinema_name = optarg;
-                       cinema = shared_ptr<Cinema> (new Cinema (optarg, list<string> (), "", 0, 0 ));
+                       cinema = shared_ptr<Cinema> (new Cinema (optarg, list<string>(), "", 0, 0));
                        break;
                case 'S':
                        screen_description = optarg;
                        break;
-               case 'C': {
-                       certificate = dcp::Certificate (dcp::file_to_string (optarg));
-                       vector<dcp::Certificate> trusted_devices;
-                       shared_ptr<Screen> screen (new Screen (screen_description, certificate, trusted_devices));
-                       if (cinema_name) {
+               case 'C':
+               {
+                       /* Make a new screen and add it to the current cinema */
+                       shared_ptr<Screen> screen (new Screen (screen_description, dcp::Certificate (dcp::file_to_string (optarg)), vector<TrustedDevice>()));
+                       if (cinema) {
                                cinema->add_screen (screen);
                        }
                        screens.push_back (screen);
                        break;
                }
                case 'T':
-                       screens.back()->trusted_devices.push_back (dcp::Certificate (dcp::file_to_string (optarg)));
+                       /* A trusted device ends up in the last screen we made */
+                       if (!screens.empty ()) {
+                               screens.back()->trusted_devices.push_back(TrustedDevice(dcp::Certificate(dcp::file_to_string(optarg))));
+                       }
                        break;
                case 'B':
                        list_cinemas = true;
@@ -539,7 +570,20 @@ int main (int argc, char* argv[])
 
        string const thing = argv[optind];
        if (boost::filesystem::is_directory(thing) && boost::filesystem::is_regular_file(boost::filesystem::path(thing) / "metadata.xml")) {
-               from_film (screens, thing, verbose, output, container_name_format, filename_format, *valid_from, *valid_to, formulation, zip);
+               from_film (
+                       screens,
+                       thing,
+                       verbose,
+                       output,
+                       container_name_format,
+                       filename_format,
+                       *valid_from,
+                       *valid_to,
+                       formulation,
+                       disable_forensic_marking_picture,
+                       disable_forensic_marking_audio,
+                       zip
+                       );
        } else {
                if (boost::filesystem::is_regular_file(thing)) {
                        dkdm = dcp::EncryptedKDM (dcp::file_to_string (thing));
@@ -551,7 +595,20 @@ int main (int argc, char* argv[])
                        error ("could not find film or CPL ID corresponding to " + thing);
                }
 
-               from_dkdm (screens, dcp::DecryptedKDM (*dkdm, Config::instance()->decryption_chain()->key().get()), verbose, output, container_name_format, filename_format, *valid_from, *valid_to, formulation, zip);
+               from_dkdm (
+                       screens,
+                       dcp::DecryptedKDM (*dkdm, Config::instance()->decryption_chain()->key().get()),
+                       verbose,
+                       output,
+                       container_name_format,
+                       filename_format,
+                       *valid_from,
+                       *valid_to,
+                       formulation,
+                       disable_forensic_marking_picture,
+                       disable_forensic_marking_audio,
+                       zip
+                       );
        }
 
        return 0;