chiark / gitweb /
make-secnet-sites: Fix error handling if caller is in wrong group
[secnet.git] / make-secnet-sites
index d9ed821dd0db152d00889d8af06e6ef072a980d4..13a6c04b7fbd77d5860b243ca467f0171ff99d28 100755 (executable)
@@ -293,34 +293,34 @@ class PkmElide(PkmBase):
 class OpBase():
        # Base case is reading a sites file from self.inputfilee.
        # And writing a sites file to self.sitesfile.
+       def positional_args(self, av):
+               if len(av.arg)>3:
+                       print("Too many arguments")
+                       sys.exit(1)
+               (self.inputfile, self.outputfile) = (av.arg + [None]*2)[0:2]
        def read_in(self):
                if self.inputfile is None:
                        self.inputlines = pfile("stdin",sys.stdin.readlines())
                else:
                        self.inputlines = pfilepath(self.inputfile)
        def write_out(self):
-               if self.sitesfile is None:
+               if self.outputfile is None:
                        f=sys.stdout
                else:
-                       f=open(self.sitesfile+"-tmp",'w')
+                       f=open(self.outputfile+"-tmp",'w')
                f.write("# sites file autogenerated by make-secnet-sites\n")
                self.write_out_heading(f)
                f.write("# use make-secnet-sites to turn this file into a\n")
                f.write("# valid /etc/secnet/sites.conf file\n\n")
                self.write_out_contents(f)
                f.write("# end of sites file\n")
-               if self.sitesfile is not None:
+               if self.outputfile is not None:
                        f.close()
-                       os.rename(self.sitesfile+"-tmp",self.sitesfile)
+                       os.rename(self.outputfile+"-tmp",self.outputfile)
 
 class OpConf(OpBase):
        opts = ['--conf']
        help = 'sites.conf generation mode (default)'
-       def positional_args(self, av):
-               if len(av.arg)>3:
-                       print("Too many arguments")
-                       sys.exit(1)
-               (self.inputfile, self.outputfile) = (av.arg + [None]*2)[0:2]
        def check_group(self,group,w): pass
        def write_out(self):
                if self.outputfile is None:
@@ -332,6 +332,19 @@ class OpConf(OpBase):
                if self.outputfile is not None:
                        os.rename(tmp_outputfile,self.outputfile)
 
+class OpFilter(OpBase):
+       opts = ['--filter']
+       help = 'sites file filtering mode'
+       def positional_arXgs(self, av):
+               if len(av.arg)!=1:
+                       print("Too many arguments")
+               (self.inputfile,) = (av.arg + [None])[0:1]
+               self.outputfile = None
+       def write_out_heading(self,f):
+               f.write("# --filter --output-version=%d\n"%output_version)
+       def write_out_contents(self,f):
+               for i in self.inputlines: f.write(i)
+
 class OpUserv(OpBase):
        opts = ['--userv','-u']
        help = 'userv service fragment update mode'
@@ -340,7 +353,7 @@ class OpUserv(OpBase):
                        print("Wrong number of arguments")
                        sys.exit(1)
                (self.header, self.groupfiledir,
-                self.sitesfile, self.group) = av.arg
+                self.outputfile, self.group) = av.arg
                self.group = Tainted(self.group,0,'command line')
                # untrusted argument from caller
                if "USERV_USER" not in os.environ:
@@ -356,7 +369,7 @@ class OpUserv(OpBase):
                for i in ugs.split():
                        if self.group==i: ok=1
                if not ok:
-                       print("caller not in group %s"%group)
+                       print("caller not in group %s"%self.group.groupname())
                        sys.exit(1)
        def check_group(self,group,w):
                if group!=self.group: complain("Incorrect group!")
@@ -408,6 +421,7 @@ def parse_args():
                        fn=(lambda v,ns,*x: setattr(ns,'opmode',how)),
                        help=how().help)
        add_opmode(OpConf)
+       add_opmode(OpFilter)
        add_opmode(OpUserv)
        ap.add_argument('--conf-key-prefix', action=ActionNoYes,
                        default=True,
@@ -577,10 +591,10 @@ class rsakey (pubkey):
                self.n=w[3].bignum_10('rsa','rsa n')
                if len(w) >= 5: w[4].email()
                self.a='rsa1'
-               self.d=base91s_encode(b'%d %s %s' %
-                                     (self.l,
-                                      self.e.encode('ascii'),
-                                      self.n.encode('ascii')))
+               self.d=base91s_encode(('%d %s %s' %
+                                      (self.l,
+                                       self.e,
+                                       self.n)).encode('ascii'))
                # ^ this allows us to use the pubkey.forsites()
                # method for output in versions>=2
        def __str__(self):