Class: Inspec::Resources::FileResource

Inherits:
Object
  • Object
show all
Includes:
FilePermissionsSelector, Utils::LinuxMountParser
Defined in:
lib/inspec/resources/file.rb

Overview

TODO: rename file_resource.rb

Direct Known Subclasses

Bond, Directory

Instance Attribute Summary collapse

Instance Method Summary collapse

Methods included from Utils::LinuxMountParser

#includes_whitespaces?, #parse_mount_options

Methods included from FilePermissionsSelector

#select_file_perms_style

Constructor Details

#initialize(path) ⇒ FileResource

Returns a new instance of FileResource.



39
40
41
42
43
# File 'lib/inspec/resources/file.rb', line 39

def initialize(path)
  # select permissions style
  @perms_provider = select_file_perms_style(inspec.os)
  @file = inspec.backend.file(path)
end

Instance Attribute Details

#fileObject (readonly)

Returns the value of attribute file.



38
39
40
# File 'lib/inspec/resources/file.rb', line 38

def file
  @file
end

#mount_optionsObject (readonly)

Returns the value of attribute mount_options.



38
39
40
# File 'lib/inspec/resources/file.rb', line 38

def mount_options
  @mount_options
end

Instance Method Details

#allowed?(permission, opts = {}) ⇒ Boolean

Returns:

  • (Boolean)


107
108
109
110
111
112
# File 'lib/inspec/resources/file.rb', line 107

def allowed?(permission, opts = {})
  return false unless exist?
  return skip_resource "`allowed?` is not supported on your OS yet." if @perms_provider.nil?

  file_permission_granted?(permission, opts[:by], opts[:by_user])
end

#contain(*_) ⇒ Object



82
83
84
# File 'lib/inspec/resources/file.rb', line 82

def contain(*_)
  raise "Contain is not supported. Please use standard RSpec matchers."
end

#contentObject



57
58
59
60
61
62
# File 'lib/inspec/resources/file.rb', line 57

def content
  res = file.content
  return nil if res.nil?

  res.force_encoding("utf-8")
end

#executable?(by_usergroup, by_specific_user) ⇒ Boolean

Returns:

  • (Boolean)


100
101
102
103
104
105
# File 'lib/inspec/resources/file.rb', line 100

def executable?(by_usergroup, by_specific_user)
  return false unless exist?
  return skip_resource "`executable?` is not supported on your OS yet." if @perms_provider.nil?

  file_permission_granted?("execute", by_usergroup, by_specific_user)
end

#inherited?Boolean

returns true if inheritance is enabled on file or folder

Returns:

  • (Boolean)


74
75
76
77
78
79
80
# File 'lib/inspec/resources/file.rb', line 74

def inherited?
  return false unless exist?

  return skip_resource "`inherited?` is not supported on your OS yet." unless inspec.os.windows?

  @perms_provider.inherited?(file)
end

#more_permissive_than?(max_mode = nil) ⇒ Boolean

Returns:

  • (Boolean)

Raises:

  • (ArgumentError)


156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
# File 'lib/inspec/resources/file.rb', line 156

def more_permissive_than?(max_mode = nil)
  return nil unless exist?
  raise ArgumentError, "You must provide a value for the `maximum allowable permission` for the file." if max_mode.nil?
  raise ArgumentError, "You must provide the `maximum permission target` as a `String`, you provided: " + max_mode.class.to_s unless max_mode.is_a?(String)
  raise ArgumentError, "The value of the `maximum permission target` should be a valid file mode in 4-digit octal format: for example, `0644` or `0777`" unless /(0)?([0-7])([0-7])([0-7])/.match?(max_mode)

  # Using the files mode and a few bit-wise calculations we can ensure a
  # file is no more permisive than desired.
  #
  # 1. Calculate the inverse of the desired mode (e.g., 0644) by XOR it with
  # 0777 (all 1s). We are interested in the bits that are currently 0 since
  # it indicates that the actual mode is more permissive than the desired mode.
  # Conversely, we dont care about the bits that are currently 1 because they
  # cannot be any more permissive and we can safely ignore them.
  #
  # 2. Calculate the above result of ANDing the actual mode and the inverse
  # mode. This will determine if any of the bits that would indicate a more
  # permissive mode are set in the actual mode.
  #
  # 3. If the result is 0000, the files mode is equal
  # to or less permissive than the desired mode (PASS). Otherwise, the files
  # mode is more permissive than the desired mode (FAIL).

  max_mode = max_mode.to_i(8)
  inv_mode = 0777 ^ max_mode
  inv_mode & file.mode != 0
end

#mounted?(expected_options = nil, identical = false) ⇒ Boolean

Returns:

  • (Boolean)


114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
# File 'lib/inspec/resources/file.rb', line 114

def mounted?(expected_options = nil, identical = false)
  mounted = file.mounted

  # return if no additional parameters have been provided
  return file.mounted? if expected_options.nil?

  # deprecation warning, this functionality will be removed in future version
  Inspec.deprecate(:file_resource_be_mounted_matchers, "The file resource `be_mounted.with` and `be_mounted.only_with` matchers are deprecated. Please use the `mount` resource instead")

  # we cannot read mount data on non-Linux systems
  return nil unless inspec.os.linux?

  # parse content if we are on linux
  @mount_options ||= parse_mount_options(mounted.stdout, true)

  if identical
    # check if the options should be identical
    @mount_options == expected_options
  else
    # otherwise compare the selected values
    @mount_options.contains(expected_options)
  end
end

#readable?(by_usergroup, by_specific_user) ⇒ Boolean

Returns:

  • (Boolean)


86
87
88
89
90
91
# File 'lib/inspec/resources/file.rb', line 86

def readable?(by_usergroup, by_specific_user)
  return false unless exist?
  return skip_resource "`readable?` is not supported on your OS yet." if @perms_provider.nil?

  file_permission_granted?("read", by_usergroup, by_specific_user)
end

#sgidObject Also known as: setgid?



144
145
146
# File 'lib/inspec/resources/file.rb', line 144

def sgid
  (mode & 02000) > 0
end

#stickyObject Also known as: sticky?



150
151
152
# File 'lib/inspec/resources/file.rb', line 150

def sticky
  (mode & 01000) > 0
end

#suidObject Also known as: setuid?



138
139
140
# File 'lib/inspec/resources/file.rb', line 138

def suid
  (mode & 04000) > 0
end

#to_sObject



184
185
186
187
188
189
190
# File 'lib/inspec/resources/file.rb', line 184

def to_s
  if file
    "File #{source_path}"
  else
    "Bad File on %s" % [inspec.backend.class]
  end
end

#user_permissionsObject

returns hash containing list of users/groups and their file permissions.



65
66
67
68
69
70
71
# File 'lib/inspec/resources/file.rb', line 65

def user_permissions
  return {} unless exist?

  return skip_resource "`user_permissions` is not supported on your OS yet." unless inspec.os.windows?

  @perms_provider.user_permissions(file)
end

#writable?(by_usergroup, by_specific_user) ⇒ Boolean

Returns:

  • (Boolean)


93
94
95
96
97
98
# File 'lib/inspec/resources/file.rb', line 93

def writable?(by_usergroup, by_specific_user)
  return false unless exist?
  return skip_resource "`writable?` is not supported on your OS yet." if @perms_provider.nil?

  file_permission_granted?("write", by_usergroup, by_specific_user)
end