Documentation
¶
Index ¶
- Constants
- Variables
- func DNSlookup(host string, server string, qtype string, timeout int) ([]string, error)
- func DetectDistro() string
- func DetectPackageManager() string
- func DetectService() string
- func GetPorts() (map[string][]net.ConnectionStat, error)
- func GetProcs() (map[string][]*process.Process, error)
- func HasCommand(cmd string) bool
- func HeaderToArray(header http.Header) (res []string)
- func IsSupportedPackageManager(p string) bool
- func LookupA(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupAAAA(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupCAA(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupCNAME(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupHost(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupMX(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupNS(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupPTR(addr string, server string, c *dns.Client, m *dns.Msg) (name []string, err error)
- func LookupSRV(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func LookupTXT(host string, server string, c *dns.Client, m *dns.Msg) (addrs []string, err error)
- func SupportedPackageManagers() []string
- type Addr
- type AlpinePackage
- type Command
- type DNS
- type DebPackage
- type DefAddr
- type DefCommand
- type DefDNS
- type DefFile
- func (f *DefFile) Contents() (io.Reader, error)
- func (f *DefFile) Exists() (bool, error)
- func (f *DefFile) Filetype() (string, error)
- func (f *DefFile) Gid() (int, error)
- func (f *DefFile) Group() (string, error)
- func (f *DefFile) LinkedTo() (string, error)
- func (f *DefFile) Md5() (string, error)
- func (f *DefFile) Mode() (string, error)
- func (f *DefFile) Owner() (string, error)
- func (f *DefFile) Path() string
- func (f *DefFile) Sha256() (string, error)
- func (f *DefFile) Sha512() (string, error)
- func (f *DefFile) Size() (int, error)
- func (f *DefFile) Uid() (int, error)
- type DefGroup
- type DefHTTP
- func (u *DefHTTP) Body() (io.Reader, error)
- func (u *DefHTTP) Close() error
- func (u *DefHTTP) Exists() (bool, error)
- func (u *DefHTTP) HTTP() string
- func (u *DefHTTP) Headers() (io.Reader, error)
- func (u *DefHTTP) ID() string
- func (u *DefHTTP) SetAllowInsecure(t bool)
- func (u *DefHTTP) SetNoFollowRedirects(t bool)
- func (u *DefHTTP) Status() (int, error)
- type DefInterface
- type DefKernelParam
- type DefMount
- func (m *DefMount) Exists() (bool, error)
- func (m *DefMount) Filesystem() (string, error)
- func (m *DefMount) ID() string
- func (m *DefMount) MountPoint() string
- func (m *DefMount) Opts() ([]string, error)
- func (m *DefMount) Source() (string, error)
- func (m *DefMount) Usage() (int, error)
- func (m *DefMount) VfsOpts() ([]string, error)
- type DefPort
- type DefProcess
- type DefSyverfile
- type DefUser
- type File
- type Group
- type HTTP
- type Interface
- type KernelParam
- type Mount
- type NullPackage
- type Package
- func NewAlpinePackage(ctx context.Context, name string, system *System, config util.Config) Package
- func NewDebPackage(ctx context.Context, name string, system *System, config util.Config) Package
- func NewNullPackage(_ context.Context, name string, system *System, config util.Config) Package
- func NewPacmanPackage(ctx context.Context, name string, system *System, config util.Config) Package
- func NewRpmPackage(ctx context.Context, name string, system *System, config util.Config) Package
- type PacmanPackage
- type Port
- type Process
- type Registry
- type RegistryView
- type Resource
- type RpmPackage
- type Service
- func NewAlpineServiceInit(ctx context.Context, service string, system *System, config util.Config) Service
- func NewServiceInit(ctx context.Context, service string, system *System, config util.Config) Service
- func NewServiceSystemd(ctx context.Context, service string, system *System, config util.Config) Service
- func NewServiceSystemdLegacy(ctx context.Context, service string, system *System, config util.Config) Service
- func NewServiceUpstart(ctx context.Context, service string, system *System, config util.Config) Service
- func NewServiceWindows(ctx context.Context, service string, system *System, config util.Config) Service
- type ServiceInit
- type ServiceSystemd
- type ServiceUpstart
- type System
- type Syverfile
- type User
Constants ¶
const DEFAULT_USER_AGENT_PREFIX = "syver/"
const USER_AGENT_HEADER_PREFIX = "user-agent:"
Variables ¶
var ( ErrNullPackage = errors.New("could not detect Package type on this system, please use --package flag to explicitly set it") ErrPackageVersionNotFound = errors.New("package version not found") )
var ErrFileOwnershipUnsupported = errors.New("file mode/owner/group is not supported on this platform")
ErrFileOwnershipUnsupported is returned by Mode, Owner, Uid, Group and Gid on Windows (system/file_windows.go) -- there is no POSIX mode/owner/group concept to report there. Following the sentinel-error idiom already used by registry (ErrRegistryUnsupported) and package (ErrNullPackage): a named, comparable error rather than a fabricated zero value with a nil error.
var ErrKernelParamUnsupported = errors.New("kernel-param is not supported on this platform (no /proc/sys); on Windows use registry: instead")
ErrKernelParamUnsupported is returned by Exists when the host has no /proc/sys filesystem to query at all -- most notably Windows, which has no procfs concept, but any other host missing procfs hits the same path.
Value is a single os.ReadFile of the key's path under procSysPath, so a missing individual key and a missing /proc/sys tree both surface as the identical os.ErrNotExist -- there is no way to distinguish "this key does not exist on a real Linux host" from "there is no procfs at all here" from that one error alone (system/kernel_param.go's Trap 1 in FEAT-010). Instead of inspecting the leaf error, Exists checks whether the base directory itself is present: if it is not, nothing was actually learned about the specific key, and that must not be reported as false, nil. See SW-5.
var ErrMountAttributeUnsupported = errors.New("mount: attribute not supported on this platform")
ErrMountAttributeUnsupported is returned by an attribute that has no meaning on the platform: opts, vfs-opts and source on Windows. An empty value with a nil error would let `opts: []` pass there for the wrong reason.
var ErrMountUnsupported = errors.New("mount: not supported on this platform")
ErrMountUnsupported is returned when a mount lookup cannot be performed at all, as distinct from a lookup that ran and found nothing (ErrMountpointNotFound). Following the sentinel-error idiom already used by registry (ErrRegistryUnsupported), package (ErrNullPackage) and file (ErrFileOwnershipUnsupported).
On Windows it is what a mountpoint that is not a drive letter unwraps to: mount: covers drive letters only there, and a folder mount point is a scope limit, not a missing path. Returning ErrMountpointNotFound for it would blame the operator's path, which is the defect FEAT-013 removed when every Windows mount check still failed that way.
var ErrMountpointNotFound = errors.New("mountpoint not found")
ErrMountpointNotFound is returned by getMount (and therefore by Exists) when the platform lookup ran and genuinely found no such mountpoint -- the common, everyday case for a path that simply isn't a separate mount. Exported (was errMountpointNotFound) so resource/mount.go's `add` path can distinguish this expected outcome from a genuine lookup failure (e.g. a timeout) rather than propagating both identically as a hard error. See FEAT-010 SW-10 / Trap 1's reasoning, applied here.
var ErrRegistryUnsupported = errors.New("registry resource is only supported on Windows")
var ErrServiceNotFound = errors.New("service not found")
ErrServiceNotFound is returned by Enabled and Running on Windows (system/service_windows.go) when the named service does not exist, instead of folding "does not exist" into "exists but is disabled/not running" -- the two used to be indistinguishable, so `service: TypoedName: {enabled: false}` passed. See FEAT-010 SW-4.
var ErrServiceRunLevelsUnsupported = errors.New("service runlevels is not supported on this platform")
ErrServiceRunLevelsUnsupported is returned by RunLevels on Windows (system/service_windows.go), which has no SysV/systemd-style runlevel concept. RunLevels previously returned (nil, nil) there, so a spec ported from Linux that sets `runlevels:` got a ContainElements failure against a nil slice with no indication Windows was the reason. See FEAT-010 S-5.
Functions ¶
func DetectDistro ¶
func DetectDistro() string
DetectDistro attempts to detect which Linux distribution this computer is using. One of "ubuntu", "redhat" (including Centos), "alpine", "arch", or "debian". If it can't decide, it returns an empty string.
func DetectPackageManager ¶
func DetectPackageManager() string
DetectPackageManager attempts to detect whether or not the system is using "dpkg", "rpm", "apk", or "pacman" package managers. It first attempts to detect the distro. If that fails, it falls back to finding package manager executables. If that fails, it returns the empty string.
func DetectService ¶
func DetectService() string
DetectService attempts to detect what kind of service management the system is using, "systemd", "upstart", "alpineinit", or "init". It looks for systemctl command to detect systemd, and falls back on DetectDistro otherwise. If it can't decide, it returns "init".
func GetPorts ¶
func GetPorts() (map[string][]net.ConnectionStat, error)
GetPorts returns the set of listening TCP/UDP ports known to the OS's connection-table backend. Failures from individual protocol lookups are joined and returned rather than silently discarded: a missing/unreadable /proc/net/{tcp,udp}{,6} file is treated as "no ports" with no error, but a file that's readable yet contains a line that can't be parsed (e.g. an unexpected IP/port encoding) does return an error, which would otherwise present as every port on that protocol simply not listening. Each protocol is queried separately (rather than via a single "all" call) specifically to preserve this per-protocol error isolation.
func HasCommand ¶
HasCommand returns whether or not an executable by this name is on the PATH.
func HeaderToArray ¶
func IsSupportedPackageManager ¶
IsSupportedPackageManager determines if p is a supported package manager
func LookupAAAA ¶
AAAA (IPv6) record lookup
func LookupCNAME ¶
CNAME record lookup
func LookupHost ¶
A and AAAA record lookup - similar to net.LookupHost
func SupportedPackageManagers ¶
func SupportedPackageManagers() []string
SupportedPackageManagers is a list of package managers we support
Types ¶
type AlpinePackage ¶
type AlpinePackage struct {
// contains filtered or unexported fields
}
func (*AlpinePackage) Exists ¶
func (p *AlpinePackage) Exists() (bool, error)
func (*AlpinePackage) Installed ¶
func (p *AlpinePackage) Installed() (bool, error)
func (*AlpinePackage) Name ¶
func (p *AlpinePackage) Name() string
func (*AlpinePackage) Versions ¶
func (p *AlpinePackage) Versions() ([]string, error)
type Command ¶
type DNS ¶
type DebPackage ¶
type DebPackage struct {
// contains filtered or unexported fields
}
func (*DebPackage) Exists ¶
func (p *DebPackage) Exists() (bool, error)
func (*DebPackage) Installed ¶
func (p *DebPackage) Installed() (bool, error)
func (*DebPackage) Name ¶
func (p *DebPackage) Name() string
func (*DebPackage) Versions ¶
func (p *DebPackage) Versions() ([]string, error)
type DefCommand ¶
type DefCommand struct {
Ctx context.Context
Timeout int
// contains filtered or unexported fields
}
func (*DefCommand) Command ¶
func (c *DefCommand) Command() string
func (*DefCommand) ExitStatus ¶
func (c *DefCommand) ExitStatus() (int, error)
type DefDNS ¶
type DefDNS struct {
Timeout int
// contains filtered or unexported fields
}
func (*DefDNS) Resolvable ¶
type DefGroup ¶
type DefGroup struct {
// contains filtered or unexported fields
}
type DefHTTP ¶
type DefHTTP struct {
RequestHeader http.Header
RequestQueryParams map[string][]string
RequestBody string
Timeout int
Username string
Password string
CAFile string
CertFile string
KeyFile string
Method string
Proxy string
// contains filtered or unexported fields
}
func (*DefHTTP) SetAllowInsecure ¶
func (*DefHTTP) SetNoFollowRedirects ¶
type DefInterface ¶
type DefInterface struct {
// contains filtered or unexported fields
}
func (*DefInterface) Addrs ¶
func (i *DefInterface) Addrs() ([]string, error)
func (*DefInterface) Exists ¶
func (i *DefInterface) Exists() (bool, error)
func (*DefInterface) ID ¶
func (i *DefInterface) ID() string
func (*DefInterface) MTU ¶
func (i *DefInterface) MTU() (int, error)
func (*DefInterface) Name ¶
func (i *DefInterface) Name() string
type DefKernelParam ¶
type DefKernelParam struct {
// contains filtered or unexported fields
}
func (*DefKernelParam) Exists ¶
func (k *DefKernelParam) Exists() (bool, error)
func (*DefKernelParam) ID ¶
func (k *DefKernelParam) ID() string
func (*DefKernelParam) Key ¶
func (k *DefKernelParam) Key() string
func (*DefKernelParam) Value ¶
func (k *DefKernelParam) Value() (string, error)
Value reads the parameter the way sysctl(8) names it: every dot in the key becomes a path separator under procSysPath, and surrounding whitespace is trimmed. This is exactly what github.com/lorenzosaino/go-sysctl's Get did, which syver used for this one call until it was replaced by these few lines.
type DefMount ¶
type DefMount struct {
Timeout int
// contains filtered or unexported fields
}
func (*DefMount) Filesystem ¶
func (*DefMount) MountPoint ¶
type DefPort ¶
type DefPort struct {
// contains filtered or unexported fields
}
type DefProcess ¶
type DefProcess struct {
// contains filtered or unexported fields
}
func (*DefProcess) Executable ¶
func (p *DefProcess) Executable() string
func (*DefProcess) Exists ¶
func (p *DefProcess) Exists() (bool, error)
func (*DefProcess) Pids ¶
func (p *DefProcess) Pids() ([]int, error)
func (*DefProcess) Running ¶
func (p *DefProcess) Running() (bool, error)
func (*DefProcess) Status ¶
func (p *DefProcess) Status() ([]string, error)
Status returns the distinct process states (e.g. "running", "zombie") seen across every PID matching this executable. A process that disappears or can't be read between the snapshot and this call is skipped rather than failing the whole result, same as GetProcs -- except when every one of them fails. See collectPerProcess.
func (*DefProcess) User ¶
func (p *DefProcess) User() ([]string, error)
User returns the distinct usernames owning every PID matching this executable. Same all-or-nothing rule as Status; see collectPerProcess.
type DefSyverfile ¶
type DefSyverfile struct {
// contains filtered or unexported fields
}
func (*DefSyverfile) Path ¶
func (g *DefSyverfile) Path() string
type DefUser ¶
type DefUser struct {
// contains filtered or unexported fields
}
func (*DefUser) Exists ¶
Exists distinguishes "user.Lookup ran and genuinely found no such user" (userLookupFoundNothing -- false, nil, unchanged) from every other failure (false, err). The distinction matters most on a domain-joined host with an unreachable domain controller: previously EVERY error, including a transport failure that learned nothing, was folded into "does not exist". See FEAT-010 SW-9 / Trap 1.
type File ¶
type File interface {
Path() string
Exists() (bool, error)
Contents() (io.Reader, error)
Mode() (string, error)
Size() (int, error)
Filetype() (string, error)
Owner() (string, error)
Uid() (int, error)
Group() (string, error)
Gid() (int, error)
LinkedTo() (string, error)
Md5() (string, error)
Sha256() (string, error)
Sha512() (string, error)
}
type HTTP ¶
type Interface ¶
type KernelParam ¶
func NewDefKernelParam ¶
type Mount ¶
type NullPackage ¶
type NullPackage struct {
// contains filtered or unexported fields
}
func (*NullPackage) Exists ¶
func (p *NullPackage) Exists() (bool, error)
func (*NullPackage) Installed ¶
func (p *NullPackage) Installed() (bool, error)
func (*NullPackage) Name ¶
func (p *NullPackage) Name() string
func (*NullPackage) Versions ¶
func (p *NullPackage) Versions() ([]string, error)
type Package ¶
type Package interface {
Name() string
Exists() (bool, error)
Installed() (bool, error)
Versions() ([]string, error)
}
func NewAlpinePackage ¶
func NewDebPackage ¶
func NewNullPackage ¶
func NewPacmanPackage ¶
type PacmanPackage ¶
type PacmanPackage struct {
// contains filtered or unexported fields
}
func (*PacmanPackage) Exists ¶
func (p *PacmanPackage) Exists() (bool, error)
func (*PacmanPackage) Installed ¶
func (p *PacmanPackage) Installed() (bool, error)
func (*PacmanPackage) Name ¶
func (p *PacmanPackage) Name() string
func (*PacmanPackage) Versions ¶
func (p *PacmanPackage) Versions() ([]string, error)
type Port ¶
type Process ¶
type Registry ¶
type Registry interface {
Key() string
Exists() (bool, error)
Value() (string, error)
Type() (string, error)
// SetView selects the WOW64 registry view this resource reads. It is part
// of the interface rather than a constructor argument because the view is
// per-resource spec syntax, while the constructor is shared with every
// other resource type and takes only global config.
//
// An unusable view is recorded and surfaces from Exists, Value and Type
// rather than being returned here, so that a bad `view:` fails the check
// that used it instead of disappearing into a constructor nobody checks.
SetView(view string) error
}
type RegistryView ¶ added in v0.12.0
type RegistryView int
RegistryView is the WOW64 view a registry read is performed against.
On 64-bit Windows some keys exist twice: 64-bit programs see one copy and 32-bit programs, redirected through WOW64, see another under Wow6432Node. A spec that does not say which it means gets whichever the running binary happens to be, which for syver is always 64-bit. Compliance work needs to be able to assert against either.
const ( // RegistryViewNative is the default and MUST behave exactly as the code did // before views existed: no view flag is added to the access mask, so the // answer is whatever the OS gives a 64-bit process. Any change here is a // silent change to every existing gossfile. RegistryViewNative RegistryView = iota RegistryView32 RegistryView64 )
func ParseRegistryView ¶ added in v0.12.0
func ParseRegistryView(view string) (RegistryView, error)
ParseRegistryView turns the spec's `view:` string into a RegistryView.
It lives in this untagged file, not in registry_windows.go, so that its tests run on Linux. The grammar is a user-facing contract and does not need a Windows host to be wrong.
func (RegistryView) String ¶ added in v0.12.0
func (v RegistryView) String() string
type RpmPackage ¶
type RpmPackage struct {
// contains filtered or unexported fields
}
func (*RpmPackage) Exists ¶
func (p *RpmPackage) Exists() (bool, error)
func (*RpmPackage) Installed ¶
func (p *RpmPackage) Installed() (bool, error)
func (*RpmPackage) Name ¶
func (p *RpmPackage) Name() string
func (*RpmPackage) Versions ¶
func (p *RpmPackage) Versions() ([]string, error)
type Service ¶
type Service interface {
Service() string
Exists() (bool, error)
Enabled() (bool, error)
Running() (bool, error)
RunLevels() ([]string, error)
}
func NewAlpineServiceInit ¶
func NewServiceInit ¶
func NewServiceSystemd ¶
func NewServiceSystemdLegacy ¶
func NewServiceUpstart ¶
func NewServiceWindows ¶
func NewServiceWindows(ctx context.Context, service string, system *System, config util.Config) Service
NewServiceWindows stub for non Windows platforms. This is needed for compilation and should never be called since DetectService() only returns "windows" on Windows platforms.
type ServiceInit ¶
type ServiceInit struct {
// contains filtered or unexported fields
}
func (*ServiceInit) Enabled ¶
func (s *ServiceInit) Enabled() (bool, error)
func (*ServiceInit) Exists ¶
func (s *ServiceInit) Exists() (bool, error)
func (*ServiceInit) RunLevels ¶
func (s *ServiceInit) RunLevels() ([]string, error)
func (*ServiceInit) Running ¶
func (s *ServiceInit) Running() (bool, error)
func (*ServiceInit) Service ¶
func (s *ServiceInit) Service() string
type ServiceSystemd ¶
type ServiceSystemd struct {
// contains filtered or unexported fields
}
func (*ServiceSystemd) Enabled ¶
func (s *ServiceSystemd) Enabled() (bool, error)
func (*ServiceSystemd) Exists ¶
func (s *ServiceSystemd) Exists() (bool, error)
func (*ServiceSystemd) RunLevels ¶
func (s *ServiceSystemd) RunLevels() ([]string, error)
func (*ServiceSystemd) Running ¶
func (s *ServiceSystemd) Running() (bool, error)
func (*ServiceSystemd) Service ¶
func (s *ServiceSystemd) Service() string
type ServiceUpstart ¶
type ServiceUpstart struct {
// contains filtered or unexported fields
}
func (*ServiceUpstart) Enabled ¶
func (s *ServiceUpstart) Enabled() (bool, error)
func (*ServiceUpstart) Exists ¶
func (s *ServiceUpstart) Exists() (bool, error)
func (*ServiceUpstart) RunLevels ¶
func (s *ServiceUpstart) RunLevels() ([]string, error)
func (*ServiceUpstart) Running ¶
func (s *ServiceUpstart) Running() (bool, error)
func (*ServiceUpstart) Service ¶
func (s *ServiceUpstart) Service() string
type System ¶
type System struct {
NewPackage func(context.Context, string, *System, util2.Config) Package
NewFile func(context.Context, string, *System, util2.Config) File
NewAddr func(context.Context, string, *System, util2.Config) Addr
NewPort func(context.Context, string, *System, util2.Config) Port
NewService func(context.Context, string, *System, util2.Config) Service
NewUser func(context.Context, string, *System, util2.Config) User
NewGroup func(context.Context, string, *System, util2.Config) Group
NewCommand func(context.Context, string, *System, util2.Config) Command
NewDNS func(context.Context, string, *System, util2.Config) DNS
NewProcess func(context.Context, string, *System, util2.Config) Process
NewSyverfile func(context.Context, string, *System, util2.Config) Syverfile
NewKernelParam func(context.Context, string, *System, util2.Config) KernelParam
NewMount func(context.Context, string, *System, util2.Config) Mount
NewInterface func(context.Context, string, *System, util2.Config) Interface
NewHTTP func(context.Context, string, *System, util2.Config) HTTP
NewRegistry func(context.Context, string, *System, util2.Config) Registry
// contains filtered or unexported fields
}
Source Files
¶
- addr.go
- command.go
- command_posix.go
- dns.go
- file.go
- file_posix.go
- group.go
- helper_command.go
- http.go
- interface.go
- kernel_param.go
- log.go
- mount.go
- mount_driveletter.go
- mount_posix.go
- package.go
- package_alpine.go
- package_deb.go
- package_pacman.go
- package_rpm.go
- port.go
- process.go
- registry.go
- registry_notwindows.go
- service.go
- service_init.go
- service_posix.go
- service_systemd.go
- service_upstart.go
- system.go
- syverfile.go
- user.go
- user_group_unix.go
- user_lookup_other.go
- user_unix.go