summaryrefslogtreecommitdiff
path: root/lib/chef/provider/group.rb
blob: bfbffe9139c8aed79c8bac318af4d16b2245673b (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
#
# Author:: AJ Christensen (<aj@chef.io>)
# Copyright:: Copyright (c) Chef Software Inc.
# License:: Apache License, Version 2.0
#
# Licensed under the Apache License, Version 2.0 (the "License");
# you may not use this file except in compliance with the License.
# You may obtain a copy of the License at
#
#     http://www.apache.org/licenses/LICENSE-2.0
#
# Unless required by applicable law or agreed to in writing, software
# distributed under the License is distributed on an "AS IS" BASIS,
# WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
# See the License for the specific language governing permissions and
# limitations under the License.
#

require_relative "../provider"
require_relative "../mixin/shell_out"
require "etc" unless defined?(Etc)

class Chef
  class Provider
    class Group < Chef::Provider
      include Chef::Mixin::ShellOut
      attr_accessor :group_exists
      attr_accessor :change_desc

      def initialize(new_resource, run_context)
        super
        @group_exists = true
      end

      def load_current_resource
        @current_resource = Chef::Resource::Group.new(new_resource.name)
        current_resource.group_name(new_resource.group_name)

        group_info = nil
        begin
          group_info = Etc.getgrnam(new_resource.group_name)
        rescue ArgumentError
          @group_exists = false
          logger.trace("#{new_resource} group does not exist")
        end

        if group_info
          new_resource.gid(group_info.gid) unless new_resource.gid
          current_resource.gid(group_info.gid)
          current_resource.members(group_info.mem)
        end

        current_resource
      end

      def define_resource_requirements
        requirements.assert(:modify) do |a|
          a.assertion { @group_exists }
          a.failure_message(Chef::Exceptions::Group, "Cannot modify #{new_resource} - group does not exist!")
          a.whyrun("Group #{new_resource} does not exist. Unless it would have been created earlier in this run, this attempt to modify it would fail.")
        end

        requirements.assert(:all_actions) do |a|
          # Make sure that the resource doesn't contain any common
          # user names in the members and exclude_members properties.
          if !new_resource.members.nil? && !new_resource.excluded_members.nil?
            common_members = new_resource.members & new_resource.excluded_members
            a.assertion { common_members.empty? }
            a.failure_message(Chef::Exceptions::ConflictingMembersInGroup, "Attempting to both add and remove users from a group: '#{common_members.join(", ")}'")
            # No why-run alternative
          end
        end
      end

      # Check to see if a group needs any changes. Populate
      # @change_desc with a description of why a change must occur
      #
      # ==== Returns
      # <true>:: If a change is required
      # <false>:: If a change is not required
      def compare_group
        @change_desc = [ ]
        if new_resource.gid.to_s != current_resource.gid.to_s
          @change_desc << "change gid #{current_resource.gid} to #{new_resource.gid}"
        end

        if new_resource.append
          missing_members = []
          new_resource.members.each do |member|
            next if has_current_group_member?(member)

            validate_member!(member)
            missing_members << member
          end
          unless missing_members.empty?
            @change_desc << "add missing member(s): #{missing_members.join(", ")}"
          end

          members_to_be_removed = []
          new_resource.excluded_members.each do |member|
            if has_current_group_member?(member)
              members_to_be_removed << member
            end
          end
          unless members_to_be_removed.empty?
            @change_desc << "remove existing member(s): #{members_to_be_removed.join(", ")}"
          end
        elsif new_resource.members != current_resource.members
          @change_desc << "replace group members with new list of members"
        end

        !@change_desc.empty?
      end

      def has_current_group_member?(member)
        current_resource.members.include?(member)
      end

      def validate_member!(member)
        # Sub-classes can do any validation if needed
        # and raise an error if validation fails
        true
      end

      action :create do
        case @group_exists
        when false
          converge_by("create group #{new_resource.group_name}") do
            create_group
            logger.info("#{new_resource} created")
          end
        else
          if compare_group
            converge_by(["alter group #{new_resource.group_name}"] + change_desc) do
              manage_group
              logger.info("#{new_resource} altered")
            end
          end
        end
      end

      action :remove do
        return unless @group_exists

        converge_by("remove group #{new_resource.group_name}") do
          remove_group
          logger.info("#{new_resource} removed")
        end
      end

      action :manage do
        return unless @group_exists && compare_group

        converge_by(["manage group #{new_resource.group_name}"] + change_desc) do
          manage_group
          logger.info("#{new_resource} managed")
        end
      end

      action :modify do
        return unless compare_group

        converge_by(["modify group #{new_resource.group_name}"] + change_desc) do
          manage_group
          logger.info("#{new_resource} modified")
        end
      end

      def create_group
        raise NotImplementedError, "subclasses of Chef::Provider::Group should define #create_group"
      end

      def manage_group
        raise NotImplementedError, "subclasses of Chef::Provider::Group should define #manage_group"
      end

      def remove_group
        raise NotImplementedError, "subclasses of Chef::Provider::Group should define #remove_group"
      end

    end
  end
end