annotate file/file.go @ 15:9b4ec6b5c23e

Add tests for multipass files.
author Paul Fisher <paul@pfish.zone>
date Thu, 29 Oct 2015 23:56:53 -0400
parents da6c493cf08a
children 00d30c67b56d
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
1 // Package file handles I/O for single password files.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
2 //
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
3 // A password file contains multiple passwords for a single user.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
4 // It starts with a banner that indicates the version of the file,
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
5 // then has entries in the format specified by auth.Entry.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
6
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
7 package file
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
8
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
9 import (
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
10 "bufio"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
11 "errors"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
12 "os"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
13 "syscall"
10
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
14 "time"
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
15
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
16 "golang.org/x/sys/unix"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
17 "pfish.zone/go/multipass/auth"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
18 )
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
19
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
20 const (
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
21 // the Banner acts as a version indicator
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
22 Banner = "# Multipass v0.1 password file"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
23 )
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
24
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
25 var (
15
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
26 // Raised when there's an error in the file format.
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
27 ErrorBadFile = errors.New("multipass/file: Invalid file format")
15
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
28
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
29 // we spin waiting for the file to become available, doubling our wait time
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
30 // every time it's unavailable. If the wait time is longer than this,
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
31 // give up. Variable so it can be set in tests.
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
32 maxDelay = time.Minute
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
33 )
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
34
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
35 type ShadowFile struct {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
36 name string
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
37 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
38
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
39 // New creates a ShadowFile for reading at the given path.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
40 // If a file needs to be created, uses the given GID to create it.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
41 func New(name string) *ShadowFile {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
42 f := new(ShadowFile)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
43 f.name = name
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
44 return f
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
45 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
46
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
47 func (f *ShadowFile) newFilename() string {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
48 return f.name + ".new"
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
49 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
50
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
51 func (f *ShadowFile) open() (*os.File, *bufio.Scanner, error) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
52 file, err := os.Open(f.name)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
53 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
54 return nil, nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
55 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
56 scanner := bufio.NewScanner(file)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
57 if !scanner.Scan() {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
58 file.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
59 return nil, nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
60 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
61 if scanner.Text() != Banner {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
62 file.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
63 return nil, nil, ErrorBadFile
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
64 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
65 return file, scanner, nil
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
66 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
67
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
68 func (f *ShadowFile) Authenticate(password string) (bool, error) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
69 file, scanner, err := f.open()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
70 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
71 return false, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
72 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
73 defer file.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
74
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
75 for scanner.Scan() {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
76 entry, err := auth.EntryFromShadow(scanner.Text())
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
77 // Skip invalid lines.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
78 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
79 continue
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
80 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
81 if entry.Authenticate(password) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
82 return true, nil
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
83 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
84 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
85 return false, nil
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
86 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
87
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
88 func (f *ShadowFile) Add(entry *auth.Entry) error {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
89 handle, err := f.openWrite()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
90 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
91 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
92 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
93 err = handle.write(entry)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
94 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
95 handle.bail()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
96 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
97 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
98 for handle.next() {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
99 if entry, err := handle.entry(); err == nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
100 // If we get an invalid entry, just skip it.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
101 if err := handle.write(entry); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
102 handle.bail()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
103 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
104 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
105 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
106 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
107 return handle.finalize()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
108 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
109
10
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
110 func (f *ShadowFile) AllEntries() ([]*auth.Entry, error) {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
111 file, scanner, err := f.open()
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
112 if err != nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
113 return nil, err
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
114 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
115 defer file.Close()
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
116
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
117 var entries []*auth.Entry
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
118
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
119 for scanner.Scan() {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
120 entry, err := auth.EntryFromShadow(scanner.Text())
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
121 // Skip invalid lines.
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
122 if err != nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
123 continue
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
124 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
125 entries = append(entries, entry)
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
126 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
127 return entries, nil
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
128 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
129
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
130 func (f *ShadowFile) Remove(id uint64) error {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
131 handle, err := f.openWrite()
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
132 if err != nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
133 return err
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
134 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
135 for handle.next() {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
136 if entry, err := handle.entry(); err == nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
137 // If we get an invalid entry, just skip it.
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
138 if entry.ID() != id {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
139 if err := handle.write(entry); err != nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
140 handle.bail()
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
141 return err
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
142 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
143 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
144 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
145 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
146 return handle.finalize()
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
147 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
148
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
149 func (f *ShadowFile) openWrite() (*writeHandle, error) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
150 return openWriteHandle(f.newFilename(), f.name)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
151 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
152
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
153 type writeHandle struct {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
154 // We write to a file handle pointing to tempName.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
155 tempName string
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
156 tempFile *os.File
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
157 writer *bufio.Writer
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
158
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
159 // It will eventually move to fileName, which is our source file.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
160 fileName string
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
161 // If inFile is nil, we're creating a new multipass file.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
162 inFile *os.File
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
163 scanner *bufio.Scanner
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
164 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
165
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
166 func openWriteHandle(tempName, fileName string) (*writeHandle, error) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
167 h := new(writeHandle)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
168 h.tempName = tempName
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
169 h.fileName = fileName
10
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
170 // Open the output file, but only if it doesn't exist.
9
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
171 // This prevents race conditions.
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
172 oldUmask := unix.Umask(077)
10
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
173 var tempFile *os.File
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
174 delay := time.Nanosecond
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
175 for tempFile == nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
176 tempTempFile, err := os.OpenFile(tempName, os.O_CREATE|os.O_EXCL|os.O_WRONLY|os.O_SYNC, 0600)
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
177 tempFile = tempTempFile
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
178 if err != nil {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
179 perr := err.(*os.PathError)
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
180 errno, ok := perr.Err.(syscall.Errno)
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
181 if !ok {
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
182 return nil, err
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
183 }
15
9b4ec6b5c23e Add tests for multipass files.
Paul Fisher <paul@pfish.zone>
parents: 13
diff changeset
184 if errno != syscall.EEXIST || delay > maxDelay {
10
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
185 return nil, err
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
186 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
187 time.Sleep(delay)
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
188 delay *= 2
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
189 }
1246b4b9028b Add tool to remove passwords.
Paul Fisher <paul@pfish.zone>
parents: 9
diff changeset
190 }
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
191 unix.Umask(oldUmask)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
192 h.tempFile = tempFile
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
193 // Open the input file.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
194 inFile, err := os.Open(fileName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
195 if err == nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
196 // Prepare to read in the input file, if it exists.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
197 h.inFile = inFile
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
198 h.scanner = bufio.NewScanner(h.inFile)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
199 if !h.scanner.Scan() {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
200 return nil, ErrorBadFile
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
201 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
202 if h.scanner.Text() != Banner {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
203 return nil, ErrorBadFile
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
204 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
205 // Change the owner and group of the new file to that of the old.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
206 inStat, err := h.inFile.Stat()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
207 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
208 h.bail()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
209 return nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
210 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
211 inStatUnix := inStat.Sys().(*syscall.Stat_t)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
212 if err := h.tempFile.Chown(int(inStatUnix.Uid), int(inStatUnix.Gid)); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
213 h.bail()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
214 return nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
215 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
216 if err := h.tempFile.Chmod(inStat.Mode()); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
217 h.bail()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
218 return nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
219 }
9
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
220 } else {
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
221 // TODO(pfish): Restrict ACL to only multipass authenticators.
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
222 if err := h.tempFile.Chmod(0644); err != nil {
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
223 h.bail()
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
224 return nil, err
e58bfc7fc207 Make multipass files default all-readable.
Paul Fisher <paul@pfish.zone>
parents: 0
diff changeset
225 }
0
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
226 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
227 h.writer = bufio.NewWriter(h.tempFile)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
228 if _, err := h.writer.WriteString(Banner + "\n"); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
229 return nil, err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
230 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
231 return h, nil
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
232 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
233
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
234 func (h *writeHandle) bail() {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
235 h.tempFile.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
236 h.inFile.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
237 os.Remove(h.tempName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
238 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
239
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
240 func (h *writeHandle) next() bool {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
241 // If the scanner is nil, then we have no input file and therefore no next.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
242 return h.scanner != nil && h.scanner.Scan()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
243 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
244
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
245 func (h *writeHandle) entry() (*auth.Entry, error) {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
246 return auth.EntryFromShadow(h.scanner.Text())
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
247 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
248
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
249 func (h *writeHandle) write(entry *auth.Entry) error {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
250 if _, err := h.writer.WriteString(entry.Encode()); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
251 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
252 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
253 _, err := h.writer.WriteString("\n")
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
254 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
255 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
256
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
257 func (h *writeHandle) finalize() error {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
258 h.inFile.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
259 // Make absolutely completely sure we're synced.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
260 if err := h.writer.Flush(); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
261 h.tempFile.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
262 os.Remove(h.tempName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
263 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
264 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
265 if err := h.tempFile.Sync(); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
266 h.tempFile.Close()
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
267 os.Remove(h.tempName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
268 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
269 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
270 // Close the file.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
271 if err := h.tempFile.Close(); err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
272 os.Remove(h.tempName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
273 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
274 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
275 // And atomically write it over the new one.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
276 err := os.Rename(h.tempName, h.fileName)
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
277 if err != nil {
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
278 return err
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
279 }
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
280 // If we get here, everything succeeded, and only in this case
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
281 // will the multipass shadow file have been updated.
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
282 return nil
c18bc7b9d1d9 Basic binaries. checkpassword doesn't yet work.
Paul Fisher <paul@pfish.zone>
parents:
diff changeset
283 }