Compare commits
2
Commits
41078f1997
...
next
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
7c6531eaf7 | ||
|
|
d52b4f1240 |
@@ -1,3 +1,9 @@
|
|||||||
|
# .git is sent without its config. Without a VERSION build argument the
|
||||||
|
# stage that compiles runs `git describe --tags --always` on .git, which
|
||||||
|
# does not need .git/config; that file can hold a credential, such as a
|
||||||
|
# password in a remote URL or the token the CI checkout step stores there.
|
||||||
|
.git/config
|
||||||
|
|
||||||
# Build artifacts
|
# Build artifacts
|
||||||
secret
|
secret
|
||||||
coverage.out
|
coverage.out
|
||||||
|
|||||||
+14
-1
@@ -27,7 +27,20 @@ RUN go mod download
|
|||||||
COPY . .
|
COPY . .
|
||||||
|
|
||||||
RUN make test
|
RUN make test
|
||||||
RUN make build
|
|
||||||
|
# The version stamped into the binary: the VERSION build argument when one
|
||||||
|
# is given, otherwise `git describe --tags --always` of the .git the build
|
||||||
|
# context carries: the tag on a tagged commit, tag-N-gHASH on a commit after
|
||||||
|
# one, the short commit when no tag is reachable. A context that carries .git
|
||||||
|
# and still yields no version fails the build.
|
||||||
|
ARG VERSION
|
||||||
|
RUN version="${VERSION:-$(git describe --tags --always)}"; \
|
||||||
|
if [ -e .git ] && { [ -z "$version" ] || [ "$version" = dev ] || \
|
||||||
|
[ "$version" = unknown ]; }; then \
|
||||||
|
echo "no version could be derived although the build context carries .git" >&2; \
|
||||||
|
exit 1; \
|
||||||
|
fi; \
|
||||||
|
make build VERSION="${version:-dev}"
|
||||||
|
|
||||||
# Runtime stage
|
# Runtime stage
|
||||||
# alpine 3.23 (2026-03-10)
|
# alpine 3.23 (2026-03-10)
|
||||||
|
|||||||
@@ -2,7 +2,7 @@ export CGO_ENABLED=1
|
|||||||
export DOCKER_HOST := ssh://root@ber1app1.local
|
export DOCKER_HOST := ssh://root@ber1app1.local
|
||||||
|
|
||||||
# Version information
|
# Version information
|
||||||
VERSION := 0.1.0
|
VERSION := $(shell git describe --tags --always --dirty 2>/dev/null || echo "dev")
|
||||||
GIT_COMMIT := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
|
GIT_COMMIT := $(shell git rev-parse HEAD 2>/dev/null || echo "unknown")
|
||||||
LDFLAGS := -X 'git.eeqj.de/sneak/secret/internal/cli.Version=$(VERSION)' \
|
LDFLAGS := -X 'git.eeqj.de/sneak/secret/internal/cli.Version=$(VERSION)' \
|
||||||
-X 'git.eeqj.de/sneak/secret/internal/cli.GitCommit=$(GIT_COMMIT)'
|
-X 'git.eeqj.de/sneak/secret/internal/cli.GitCommit=$(GIT_COMMIT)'
|
||||||
|
|||||||
@@ -25,6 +25,19 @@ Bring the repo into policy compliance in one commit:
|
|||||||
|
|
||||||
# Completed Steps
|
# Completed Steps
|
||||||
|
|
||||||
|
- 2026-10-03: The keychain unlocker's age key passphrase stays in
|
||||||
|
locked memory: it is generated into a locked buffer, and the
|
||||||
|
keychain JSON is written and read by `KeychainData` code in
|
||||||
|
`internal/secret/keychaindata.go` (tested on Linux) without
|
||||||
|
`encoding/json` holding it; the JSON field names are unchanged.
|
||||||
|
- 2026-10-02: A plain `docker build .` builds again: the size tests
|
||||||
|
skip a case that needs more locked memory than the process can
|
||||||
|
lock, and run every case under `script/cibuild`. The image stamps the
|
||||||
|
`VERSION` build argument, else `git describe --tags --always`, into
|
||||||
|
`Version`, and fails if `.git` is present but yields no version;
|
||||||
|
`make build` stamps `git describe` too, not a fixed `0.1.0`.
|
||||||
|
`.dockerignore` keeps `.git/config` out; `script/docker` is the
|
||||||
|
canonical copy.
|
||||||
- 2026-08-07: Updated golangci-lint to v2.12.2 with the canonical
|
- 2026-08-07: Updated golangci-lint to v2.12.2 with the canonical
|
||||||
`.golangci.yml` (all linters enabled minus the standard disable
|
`.golangci.yml` (all linters enabled minus the standard disable
|
||||||
list, `lll` 88, tests linted); bumped the `Dockerfile` lint-stage
|
list, `lll` 88, tests linted); bumped the `Dockerfile` lint-stage
|
||||||
@@ -80,12 +93,11 @@ Bring the repo into policy compliance in one commit:
|
|||||||
- Command injection: GPG key IDs passed unescaped to exec.Command
|
- Command injection: GPG key IDs passed unescaped to exec.Command
|
||||||
(pgpunlocker.go:323-327); data.String() passed unescaped to the
|
(pgpunlocker.go:323-327); data.String() passed unescaped to the
|
||||||
security command (keychainunlocker.go:472-476).
|
security command (keychainunlocker.go:472-476).
|
||||||
- Memory security: KeychainData stores AgePrivKeyPassphrase as a
|
- Memory security: age identity .String() creates unprotected
|
||||||
plain string (keychainunlocker.go:342,393-396); age identity
|
copies (keychainunlocker.go:356, pgpunlocker.go:256,
|
||||||
.String() creates unprotected copies (keychainunlocker.go:356,
|
version.go:155); age secret key held in a plain string in
|
||||||
pgpunlocker.go:256, version.go:155); age secret key held in a
|
cli/crypto.go:86,91,113; private keys exposed via buffer.Bytes()
|
||||||
plain string in cli/crypto.go:86,91,113; private keys exposed via
|
to GPGEncryptFunc and EncryptWithPassphrase.
|
||||||
buffer.Bytes() to GPGEncryptFunc and EncryptWithPassphrase.
|
|
||||||
- Race conditions: no file locking in vault/secrets.go:142-176;
|
- Race conditions: no file locking in vault/secrets.go:142-176;
|
||||||
non-atomic writes can leave the vault inconsistent.
|
non-atomic writes can leave the vault inconsistent.
|
||||||
- Input validation: dots in secret names risk path traversal
|
- Input validation: dots in secret names risk path traversal
|
||||||
|
|||||||
@@ -16,6 +16,7 @@ require (
|
|||||||
github.com/stretchr/testify v1.8.4
|
github.com/stretchr/testify v1.8.4
|
||||||
github.com/tyler-smith/go-bip39 v1.1.0
|
github.com/tyler-smith/go-bip39 v1.1.0
|
||||||
golang.org/x/crypto v0.38.0
|
golang.org/x/crypto v0.38.0
|
||||||
|
golang.org/x/sys v0.33.0
|
||||||
golang.org/x/term v0.32.0
|
golang.org/x/term v0.32.0
|
||||||
)
|
)
|
||||||
|
|
||||||
@@ -31,7 +32,6 @@ require (
|
|||||||
github.com/mattn/go-isatty v0.0.20 // indirect
|
github.com/mattn/go-isatty v0.0.20 // indirect
|
||||||
github.com/pmezard/go-difflib v1.0.0 // indirect
|
github.com/pmezard/go-difflib v1.0.0 // indirect
|
||||||
github.com/spf13/pflag v1.0.6 // indirect
|
github.com/spf13/pflag v1.0.6 // indirect
|
||||||
golang.org/x/sys v0.33.0 // indirect
|
|
||||||
golang.org/x/text v0.25.0 // indirect
|
golang.org/x/text v0.25.0 // indirect
|
||||||
gopkg.in/yaml.v3 v3.0.1 // indirect
|
gopkg.in/yaml.v3 v3.0.1 // indirect
|
||||||
)
|
)
|
||||||
|
|||||||
@@ -17,11 +17,51 @@ import (
|
|||||||
"github.com/spf13/cobra"
|
"github.com/spf13/cobra"
|
||||||
"github.com/stretchr/testify/assert"
|
"github.com/stretchr/testify/assert"
|
||||||
"github.com/stretchr/testify/require"
|
"github.com/stretchr/testify/require"
|
||||||
|
"golang.org/x/sys/unix"
|
||||||
)
|
)
|
||||||
|
|
||||||
// testVaultName is the vault name used by the size tests.
|
// testVaultName is the vault name used by the size tests.
|
||||||
const testVaultName = "test-vault"
|
const testVaultName = "test-vault"
|
||||||
|
|
||||||
|
// lockedBytesPerSecretByte bounds the locked memory that storing a secret
|
||||||
|
// holds at once: the buffers it is read into reach up to 1.5 times its
|
||||||
|
// size, and they are then copied into one more buffer of its size.
|
||||||
|
const lockedBytesPerSecretByte = 3
|
||||||
|
|
||||||
|
// skipIfLockedMemoryTooLow skips the test when this process cannot lock
|
||||||
|
// the memory a secret of size bytes needs, found by locking a buffer of
|
||||||
|
// that size and releasing it. memguard panics, ending the whole test run,
|
||||||
|
// when it cannot lock a buffer, and a plain `docker build .` runs the
|
||||||
|
// tests under an 8 MiB locked-memory limit (RLIMIT_MEMLOCK). A process
|
||||||
|
// allowed to lock past that limit runs every case.
|
||||||
|
func skipIfLockedMemoryTooLow(t *testing.T, size int) {
|
||||||
|
t.Helper()
|
||||||
|
|
||||||
|
need := lockedBytesPerSecretByte * size
|
||||||
|
|
||||||
|
buf, err := unix.Mmap(-1, 0, need,
|
||||||
|
unix.PROT_READ|unix.PROT_WRITE, unix.MAP_PRIVATE|unix.MAP_ANON)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
lockErr := unix.Mlock(buf)
|
||||||
|
|
||||||
|
// Unmapping the buffer also unlocks it.
|
||||||
|
err = unix.Munmap(buf)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
if lockErr != nil {
|
||||||
|
var limit unix.Rlimit
|
||||||
|
|
||||||
|
err = unix.Getrlimit(unix.RLIMIT_MEMLOCK, &limit)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
t.Skipf("a %d-byte secret needs up to %d bytes of locked memory, "+
|
||||||
|
"which could not be locked under the locked-memory limit "+
|
||||||
|
"(RLIMIT_MEMLOCK) of %d bytes: %v",
|
||||||
|
size, need, limit.Cur, lockErr)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
// newSizeTestVault creates an in-memory vault unlocked with the test
|
// newSizeTestVault creates an in-memory vault unlocked with the test
|
||||||
// mnemonic and returns the filesystem and vault.
|
// mnemonic and returns the filesystem and vault.
|
||||||
//
|
//
|
||||||
@@ -59,6 +99,7 @@ func newSizeTestVault(t *testing.T) (afero.Fs, *vault.Vault) {
|
|||||||
// verifies the outcome.
|
// verifies the outcome.
|
||||||
func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
skipIfLockedMemoryTooLow(t, size)
|
||||||
|
|
||||||
fs, vlt := newSizeTestVault(t)
|
fs, vlt := newSizeTestVault(t)
|
||||||
|
|
||||||
@@ -110,6 +151,7 @@ func runAddSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
|||||||
// verifies the outcome.
|
// verifies the outcome.
|
||||||
func runImportSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
func runImportSecretSizeCase(t *testing.T, size int, wantErr bool, errMsg string) {
|
||||||
t.Helper()
|
t.Helper()
|
||||||
|
skipIfLockedMemoryTooLow(t, size)
|
||||||
|
|
||||||
fs, vlt := newSizeTestVault(t)
|
fs, vlt := newSizeTestVault(t)
|
||||||
|
|
||||||
@@ -300,6 +342,8 @@ func TestAddSecretBufferGrowth(t *testing.T) {
|
|||||||
|
|
||||||
for _, size := range sizes {
|
for _, size := range sizes {
|
||||||
t.Run(fmt.Sprintf("size_%d", size), func(t *testing.T) {
|
t.Run(fmt.Sprintf("size_%d", size), func(t *testing.T) {
|
||||||
|
skipIfLockedMemoryTooLow(t, size)
|
||||||
|
|
||||||
fs, vlt := newSizeTestVault(t)
|
fs, vlt := newSizeTestVault(t)
|
||||||
|
|
||||||
// Create test data of exactly the specified size
|
// Create test data of exactly the specified size
|
||||||
|
|||||||
@@ -1,29 +0,0 @@
|
|||||||
//go:build darwin
|
|
||||||
|
|
||||||
package secret
|
|
||||||
|
|
||||||
import (
|
|
||||||
"crypto/rand"
|
|
||||||
"fmt"
|
|
||||||
"math/big"
|
|
||||||
)
|
|
||||||
|
|
||||||
// generateRandomString generates a random string of the specified length using the given character set
|
|
||||||
func generateRandomString(length int, charset string) (string, error) {
|
|
||||||
if length <= 0 {
|
|
||||||
return "", fmt.Errorf("length must be positive")
|
|
||||||
}
|
|
||||||
|
|
||||||
result := make([]byte, length)
|
|
||||||
charsetLen := big.NewInt(int64(len(charset)))
|
|
||||||
|
|
||||||
for i := range length {
|
|
||||||
randomIndex, err := rand.Int(rand.Reader, charsetLen)
|
|
||||||
if err != nil {
|
|
||||||
return "", fmt.Errorf("failed to generate random number: %w", err)
|
|
||||||
}
|
|
||||||
result[i] = charset[randomIndex.Int64()]
|
|
||||||
}
|
|
||||||
|
|
||||||
return string(result), nil
|
|
||||||
}
|
|
||||||
@@ -0,0 +1,142 @@
|
|||||||
|
package secret
|
||||||
|
|
||||||
|
import (
|
||||||
|
"bytes"
|
||||||
|
"encoding/hex"
|
||||||
|
"encoding/json"
|
||||||
|
"errors"
|
||||||
|
"fmt"
|
||||||
|
"strings"
|
||||||
|
|
||||||
|
"github.com/awnumar/memguard"
|
||||||
|
)
|
||||||
|
|
||||||
|
var (
|
||||||
|
errPassphraseLength = errors.New(
|
||||||
|
"passphrase length must be a positive even number")
|
||||||
|
errPassphraseNotHex = errors.New(
|
||||||
|
"keychain passphrase must be lowercase hex")
|
||||||
|
errNoKeychainPassphrase = errors.New(
|
||||||
|
"keychain data has no agePrivKeyPassphrase string")
|
||||||
|
)
|
||||||
|
|
||||||
|
// KeychainData is what a keychain unlocker stores in the macOS keychain.
|
||||||
|
// It is stored as JSON, but encode and decodeKeychainData keep the
|
||||||
|
// passphrase out of encoding/json, which would leave copies of it in
|
||||||
|
// ordinary memory.
|
||||||
|
type KeychainData struct {
|
||||||
|
AgePublicKey string
|
||||||
|
AgePrivKeyPassphrase *memguard.LockedBuffer
|
||||||
|
EncryptedLongtermKey string
|
||||||
|
}
|
||||||
|
|
||||||
|
// generateRandomPassphrase returns length random lowercase hex characters
|
||||||
|
// in a locked buffer. The caller must destroy it.
|
||||||
|
func generateRandomPassphrase(length int) (*memguard.LockedBuffer, error) {
|
||||||
|
// Each random byte becomes two hex characters.
|
||||||
|
randomBytes := hex.DecodedLen(length)
|
||||||
|
if length <= 0 || hex.EncodedLen(randomBytes) != length {
|
||||||
|
return nil, errPassphraseLength
|
||||||
|
}
|
||||||
|
|
||||||
|
random := memguard.NewBufferRandom(randomBytes)
|
||||||
|
defer random.Destroy()
|
||||||
|
|
||||||
|
passphrase := memguard.NewBuffer(length)
|
||||||
|
hex.Encode(passphrase.Bytes(), random.Bytes())
|
||||||
|
passphrase.Freeze()
|
||||||
|
|
||||||
|
return passphrase, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// encode returns d as JSON in a locked buffer:
|
||||||
|
// {"agePublicKey":"...","agePrivKeyPassphrase":"...","encryptedLongtermKey":"..."}.
|
||||||
|
// The passphrase is copied straight into the buffer, so it must be hex,
|
||||||
|
// which JSON does not escape. The caller must destroy the returned buffer.
|
||||||
|
func (d *KeychainData) encode() (*memguard.LockedBuffer, error) {
|
||||||
|
if d.AgePrivKeyPassphrase == nil {
|
||||||
|
return nil, errNilPassphraseBuffer
|
||||||
|
}
|
||||||
|
|
||||||
|
if d.AgePrivKeyPassphrase.Size() == 0 {
|
||||||
|
return nil, errEmptyPassphrase
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, c := range d.AgePrivKeyPassphrase.Bytes() {
|
||||||
|
if strings.IndexByte("0123456789abcdef", c) < 0 {
|
||||||
|
return nil, errPassphraseNotHex
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
publicKey, err := json.Marshal(d.AgePublicKey)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to encode age public key: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
longtermKey, err := json.Marshal(d.EncryptedLongtermKey)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to encode long-term key: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
parts := [][]byte{
|
||||||
|
[]byte(`{"agePublicKey":`), publicKey,
|
||||||
|
[]byte(`,"agePrivKeyPassphrase":"`), d.AgePrivKeyPassphrase.Bytes(),
|
||||||
|
[]byte(`","encryptedLongtermKey":`), longtermKey,
|
||||||
|
[]byte(`}`),
|
||||||
|
}
|
||||||
|
|
||||||
|
size := 0
|
||||||
|
for _, part := range parts {
|
||||||
|
size += len(part)
|
||||||
|
}
|
||||||
|
|
||||||
|
encoded := memguard.NewBuffer(size)
|
||||||
|
|
||||||
|
written := 0
|
||||||
|
for _, part := range parts {
|
||||||
|
written += copy(encoded.Bytes()[written:], part)
|
||||||
|
}
|
||||||
|
|
||||||
|
encoded.Freeze()
|
||||||
|
|
||||||
|
return encoded, nil
|
||||||
|
}
|
||||||
|
|
||||||
|
// decodeKeychainData parses keychain data written by encode. The caller
|
||||||
|
// must destroy the returned AgePrivKeyPassphrase.
|
||||||
|
func decodeKeychainData(data *memguard.LockedBuffer) (*KeychainData, error) {
|
||||||
|
if data == nil {
|
||||||
|
return nil, errNilDataBuffer
|
||||||
|
}
|
||||||
|
|
||||||
|
// json.Unmarshal gives a json.RawMessage field the field's JSON text
|
||||||
|
// unchanged, in the one copy RawMessage makes; it is wiped on return.
|
||||||
|
var fields struct {
|
||||||
|
AgePublicKey string `json:"agePublicKey"`
|
||||||
|
AgePrivKeyPassphrase json.RawMessage `json:"agePrivKeyPassphrase"`
|
||||||
|
EncryptedLongtermKey string `json:"encryptedLongtermKey"`
|
||||||
|
}
|
||||||
|
|
||||||
|
defer func() { memguard.WipeBytes(fields.AgePrivKeyPassphrase) }()
|
||||||
|
|
||||||
|
err := json.Unmarshal(data.Bytes(), &fields)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("failed to parse keychain data: %w", err)
|
||||||
|
}
|
||||||
|
|
||||||
|
// json.Unmarshal accepted the JSON, so text that starts with a quote is
|
||||||
|
// a whole string. The passphrase is hex, so it is the text between the
|
||||||
|
// quotes.
|
||||||
|
quoted := fields.AgePrivKeyPassphrase
|
||||||
|
if !bytes.HasPrefix(quoted, []byte(`"`)) {
|
||||||
|
return nil, errNoKeychainPassphrase
|
||||||
|
}
|
||||||
|
|
||||||
|
return &KeychainData{
|
||||||
|
AgePublicKey: fields.AgePublicKey,
|
||||||
|
// NewBufferFromBytes wipes the bytes it copies.
|
||||||
|
AgePrivKeyPassphrase: memguard.NewBufferFromBytes(
|
||||||
|
quoted[1 : len(quoted)-1]),
|
||||||
|
EncryptedLongtermKey: fields.EncryptedLongtermKey,
|
||||||
|
}, nil
|
||||||
|
}
|
||||||
@@ -0,0 +1,118 @@
|
|||||||
|
//nolint:testpackage // white-box test of unexported internals
|
||||||
|
package secret
|
||||||
|
|
||||||
|
import (
|
||||||
|
"encoding/json"
|
||||||
|
"testing"
|
||||||
|
|
||||||
|
"github.com/awnumar/memguard"
|
||||||
|
"github.com/stretchr/testify/assert"
|
||||||
|
"github.com/stretchr/testify/require"
|
||||||
|
)
|
||||||
|
|
||||||
|
func TestGenerateRandomPassphrase(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
first, err := generateRandomPassphrase(64)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
defer first.Destroy()
|
||||||
|
|
||||||
|
second, err := generateRandomPassphrase(64)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
defer second.Destroy()
|
||||||
|
|
||||||
|
assert.Regexp(t, `^[0-9a-f]{64}$`, first.String())
|
||||||
|
assert.NotEqual(t, first.String(), second.String())
|
||||||
|
assert.False(t, first.IsMutable())
|
||||||
|
|
||||||
|
for _, length := range []int{0, -2, 63} {
|
||||||
|
_, err := generateRandomPassphrase(length)
|
||||||
|
require.ErrorIs(t, err, errPassphraseLength, "length %d", length)
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestKeychainDataEncodeDecode(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
passphrase := memguard.NewBufferFromBytes([]byte("0a1b2c3d"))
|
||||||
|
defer passphrase.Destroy()
|
||||||
|
|
||||||
|
data := KeychainData{
|
||||||
|
AgePublicKey: "age1example",
|
||||||
|
AgePrivKeyPassphrase: passphrase,
|
||||||
|
EncryptedLongtermKey: "beef",
|
||||||
|
}
|
||||||
|
|
||||||
|
encoded, err := data.encode()
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
defer encoded.Destroy()
|
||||||
|
|
||||||
|
assert.JSONEq(t,
|
||||||
|
`{"agePublicKey":"age1example",`+
|
||||||
|
`"agePrivKeyPassphrase":"0a1b2c3d",`+
|
||||||
|
`"encryptedLongtermKey":"beef"}`,
|
||||||
|
encoded.String())
|
||||||
|
assert.False(t, encoded.IsMutable())
|
||||||
|
|
||||||
|
decoded, err := decodeKeychainData(encoded)
|
||||||
|
require.NoError(t, err)
|
||||||
|
|
||||||
|
defer decoded.AgePrivKeyPassphrase.Destroy()
|
||||||
|
|
||||||
|
assert.Equal(t, "age1example", decoded.AgePublicKey)
|
||||||
|
assert.Equal(t, "0a1b2c3d", decoded.AgePrivKeyPassphrase.String())
|
||||||
|
assert.Equal(t, "beef", decoded.EncryptedLongtermKey)
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestKeychainDataEncodeRejectsBadPassphrase(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
tests := []struct {
|
||||||
|
name string
|
||||||
|
passphrase *memguard.LockedBuffer
|
||||||
|
wantErr error
|
||||||
|
}{
|
||||||
|
{"nil", nil, errNilPassphraseBuffer},
|
||||||
|
{"empty", memguard.NewBuffer(0), errEmptyPassphrase},
|
||||||
|
{
|
||||||
|
"not hex",
|
||||||
|
memguard.NewBufferFromBytes([]byte(`abc"def`)),
|
||||||
|
errPassphraseNotHex,
|
||||||
|
},
|
||||||
|
}
|
||||||
|
|
||||||
|
for _, tt := range tests {
|
||||||
|
t.Run(tt.name, func(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
data := KeychainData{AgePrivKeyPassphrase: tt.passphrase}
|
||||||
|
_, err := data.encode()
|
||||||
|
require.ErrorIs(t, err, tt.wantErr)
|
||||||
|
})
|
||||||
|
}
|
||||||
|
}
|
||||||
|
|
||||||
|
func TestDecodeKeychainDataRejectsBadData(t *testing.T) {
|
||||||
|
t.Parallel()
|
||||||
|
|
||||||
|
for _, text := range []string{
|
||||||
|
`{"agePublicKey":"age1example"}`,
|
||||||
|
`{"agePrivKeyPassphrase":42}`,
|
||||||
|
} {
|
||||||
|
data := memguard.NewBufferFromBytes([]byte(text))
|
||||||
|
_, err := decodeKeychainData(data)
|
||||||
|
data.Destroy()
|
||||||
|
require.ErrorIs(t, err, errNoKeychainPassphrase, text)
|
||||||
|
}
|
||||||
|
|
||||||
|
notJSON := memguard.NewBufferFromBytes([]byte(`{"agePrivKeyPassphrase":`))
|
||||||
|
defer notJSON.Destroy()
|
||||||
|
|
||||||
|
_, err := decodeKeychainData(notJSON)
|
||||||
|
|
||||||
|
var syntaxError *json.SyntaxError
|
||||||
|
require.ErrorAs(t, err, &syntaxError)
|
||||||
|
}
|
||||||
@@ -45,13 +45,6 @@ type KeychainUnlocker struct {
|
|||||||
fs afero.Fs
|
fs afero.Fs
|
||||||
}
|
}
|
||||||
|
|
||||||
// KeychainData represents the data stored in the macOS keychain
|
|
||||||
type KeychainData struct {
|
|
||||||
AgePublicKey string `json:"agePublicKey"`
|
|
||||||
AgePrivKeyPassphrase string `json:"agePrivKeyPassphrase"`
|
|
||||||
EncryptedLongtermKey string `json:"encryptedLongtermKey"`
|
|
||||||
}
|
|
||||||
|
|
||||||
// GetIdentity implements Unlocker interface for Keychain-based unlockers
|
// GetIdentity implements Unlocker interface for Keychain-based unlockers
|
||||||
func (k *KeychainUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
func (k *KeychainUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
||||||
DebugWith("Getting keychain unlocker identity",
|
DebugWith("Getting keychain unlocker identity",
|
||||||
@@ -81,13 +74,18 @@ func (k *KeychainUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
|||||||
slog.Int("data_length", len(keychainDataBytes)),
|
slog.Int("data_length", len(keychainDataBytes)),
|
||||||
)
|
)
|
||||||
|
|
||||||
|
// Move the keychain data into locked memory; this wipes keychainDataBytes
|
||||||
|
keychainDataBuffer := memguard.NewBufferFromBytes(keychainDataBytes)
|
||||||
|
defer keychainDataBuffer.Destroy()
|
||||||
|
|
||||||
// Step 3: Parse keychain data
|
// Step 3: Parse keychain data
|
||||||
var keychainData KeychainData
|
keychainData, err := decodeKeychainData(keychainDataBuffer)
|
||||||
if err := json.Unmarshal(keychainDataBytes, &keychainData); err != nil {
|
if err != nil {
|
||||||
Debug("Failed to parse keychain data", "error", err, "unlocker_id", k.GetID())
|
Debug("Failed to parse keychain data", "error", err, "unlocker_id", k.GetID())
|
||||||
|
|
||||||
return nil, fmt.Errorf("failed to parse keychain data: %w", err)
|
return nil, fmt.Errorf("failed to parse keychain data: %w", err)
|
||||||
}
|
}
|
||||||
|
defer keychainData.AgePrivKeyPassphrase.Destroy()
|
||||||
|
|
||||||
Debug("Parsed keychain data successfully", "unlocker_id", k.GetID())
|
Debug("Parsed keychain data successfully", "unlocker_id", k.GetID())
|
||||||
|
|
||||||
@@ -109,11 +107,7 @@ func (k *KeychainUnlocker) GetIdentity() (*age.X25519Identity, error) {
|
|||||||
|
|
||||||
// Step 5: Decrypt the age private key using the passphrase from keychain
|
// Step 5: Decrypt the age private key using the passphrase from keychain
|
||||||
Debug("Decrypting age private key with keychain passphrase", "unlocker_id", k.GetID())
|
Debug("Decrypting age private key with keychain passphrase", "unlocker_id", k.GetID())
|
||||||
// Create secure buffer for the keychain passphrase
|
agePrivKeyBuffer, err := DecryptWithPassphrase(encryptedAgePrivKeyData, keychainData.AgePrivKeyPassphrase)
|
||||||
passphraseBuffer := memguard.NewBufferFromBytes([]byte(keychainData.AgePrivKeyPassphrase))
|
|
||||||
defer passphraseBuffer.Destroy()
|
|
||||||
|
|
||||||
agePrivKeyBuffer, err := DecryptWithPassphrase(encryptedAgePrivKeyData, passphraseBuffer)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
Debug("Failed to decrypt age private key with keychain passphrase", "error", err, "unlocker_id", k.GetID())
|
Debug("Failed to decrypt age private key with keychain passphrase", "error", err, "unlocker_id", k.GetID())
|
||||||
|
|
||||||
@@ -369,6 +363,7 @@ func CreateKeychainUnlocker(fs afero.Fs, stateDir string) (*KeychainUnlocker, er
|
|||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("failed to generate age private key passphrase: %w", err)
|
return nil, fmt.Errorf("failed to generate age private key passphrase: %w", err)
|
||||||
}
|
}
|
||||||
|
defer agePrivKeyPassphrase.Destroy()
|
||||||
|
|
||||||
// Step 3: Store age recipient as plaintext
|
// Step 3: Store age recipient as plaintext
|
||||||
ageRecipient := ageIdentity.Recipient().String()
|
ageRecipient := ageIdentity.Recipient().String()
|
||||||
@@ -378,15 +373,12 @@ func CreateKeychainUnlocker(fs afero.Fs, stateDir string) (*KeychainUnlocker, er
|
|||||||
}
|
}
|
||||||
|
|
||||||
// Step 4: Encrypt age private key with the generated passphrase and store on disk
|
// Step 4: Encrypt age private key with the generated passphrase and store on disk
|
||||||
// Create secure buffers for both the private key and passphrase
|
// Create a secure buffer for the private key
|
||||||
agePrivKeyStr := ageIdentity.String()
|
agePrivKeyStr := ageIdentity.String()
|
||||||
agePrivKeyBuffer := memguard.NewBufferFromBytes([]byte(agePrivKeyStr))
|
agePrivKeyBuffer := memguard.NewBufferFromBytes([]byte(agePrivKeyStr))
|
||||||
defer agePrivKeyBuffer.Destroy()
|
defer agePrivKeyBuffer.Destroy()
|
||||||
|
|
||||||
passphraseBuffer := memguard.NewBufferFromBytes([]byte(agePrivKeyPassphrase))
|
encryptedAgePrivKey, err := EncryptWithPassphrase(agePrivKeyBuffer, agePrivKeyPassphrase)
|
||||||
defer passphraseBuffer.Destroy()
|
|
||||||
|
|
||||||
encryptedAgePrivKey, err := EncryptWithPassphrase(agePrivKeyBuffer, passphraseBuffer)
|
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("failed to encrypt age private key with passphrase: %w", err)
|
return nil, fmt.Errorf("failed to encrypt age private key with passphrase: %w", err)
|
||||||
}
|
}
|
||||||
@@ -422,13 +414,10 @@ func CreateKeychainUnlocker(fs afero.Fs, stateDir string) (*KeychainUnlocker, er
|
|||||||
EncryptedLongtermKey: hex.EncodeToString(encryptedLtPrivKeyToAge),
|
EncryptedLongtermKey: hex.EncodeToString(encryptedLtPrivKeyToAge),
|
||||||
}
|
}
|
||||||
|
|
||||||
keychainDataBytes, err := json.Marshal(keychainData)
|
keychainDataBuffer, err := keychainData.encode()
|
||||||
if err != nil {
|
if err != nil {
|
||||||
return nil, fmt.Errorf("failed to marshal keychain data: %w", err)
|
return nil, fmt.Errorf("failed to encode keychain data: %w", err)
|
||||||
}
|
}
|
||||||
|
|
||||||
// Create a secure buffer for keychain data
|
|
||||||
keychainDataBuffer := memguard.NewBufferFromBytes(keychainDataBytes)
|
|
||||||
defer keychainDataBuffer.Destroy()
|
defer keychainDataBuffer.Destroy()
|
||||||
|
|
||||||
// Step 8: Store data in keychain
|
// Step 8: Store data in keychain
|
||||||
@@ -501,7 +490,7 @@ func storeInKeychain(itemName string, data *memguard.LockedBuffer) error {
|
|||||||
item.SetAccount(itemName)
|
item.SetAccount(itemName)
|
||||||
item.SetLabel(fmt.Sprintf("%s - %s", KEYCHAIN_APP_IDENTIFIER, itemName))
|
item.SetLabel(fmt.Sprintf("%s - %s", KEYCHAIN_APP_IDENTIFIER, itemName))
|
||||||
item.SetDescription("Secret vault keychain data")
|
item.SetDescription("Secret vault keychain data")
|
||||||
item.SetData([]byte(data.String()))
|
item.SetData(data.Bytes())
|
||||||
item.SetSynchronizable(keychain.SynchronizableNo)
|
item.SetSynchronizable(keychain.SynchronizableNo)
|
||||||
// Use AccessibleWhenUnlockedThisDeviceOnly for better security and to trigger auth
|
// Use AccessibleWhenUnlockedThisDeviceOnly for better security and to trigger auth
|
||||||
item.SetAccessible(keychain.AccessibleWhenUnlockedThisDeviceOnly)
|
item.SetAccessible(keychain.AccessibleWhenUnlockedThisDeviceOnly)
|
||||||
@@ -576,8 +565,3 @@ func deleteFromKeychain(itemName string) error {
|
|||||||
|
|
||||||
return nil
|
return nil
|
||||||
}
|
}
|
||||||
|
|
||||||
// generateRandomPassphrase generates a random passphrase for encrypting the age private key
|
|
||||||
func generateRandomPassphrase(length int) (string, error) {
|
|
||||||
return generateRandomString(length, "0123456789abcdef")
|
|
||||||
}
|
|
||||||
|
|||||||
+3
-2
@@ -1,8 +1,9 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
# script/cibuild: run the CI build. The Dockerfile runs script/check
|
||||||
# (via make check), so a successful build implies all checks pass.
|
# (via make check), so a successful build implies all checks pass.
|
||||||
# The Gitea workflow runs this on push. The memlock ulimit is required
|
# The Gitea workflow runs this on push. The memlock ulimit lets the tests
|
||||||
# because the test suite uses memguard, which mlocks memory.
|
# that lock large secrets in memory (memguard mlocks them) run; under the
|
||||||
|
# lower limit of a plain `docker build .` they are skipped.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
ROOT="$(cd "$(dirname "$0")/.." && pwd -P)"
|
||||||
|
|||||||
+11
-2
@@ -1,7 +1,8 @@
|
|||||||
#!/bin/sh
|
#!/bin/sh
|
||||||
# script/docker: build the Docker image tagged with the project name.
|
# script/docker: build the Docker image tagged with the project name.
|
||||||
# Identical in all repos; the tag comes from script/projectname.
|
# Identical in all repos; the tag comes from script/projectname.
|
||||||
# Generic: needs no adaptation.
|
# --no-cache because the gate phases the final stage depends on are RUN
|
||||||
|
# steps, and a cached one is a check that did not run.
|
||||||
set -eu
|
set -eu
|
||||||
|
|
||||||
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
SCRIPT_DIR="$(cd "$(dirname "$0")" && pwd -P)"
|
||||||
@@ -9,7 +10,15 @@ ROOT="$(cd "$SCRIPT_DIR/.." && pwd -P)"
|
|||||||
|
|
||||||
main() {
|
main() {
|
||||||
cd "$ROOT"
|
cd "$ROOT"
|
||||||
docker build -t "$("$SCRIPT_DIR/projectname")" .
|
# Own line: a failing command substitution inside an argument does
|
||||||
|
# not trip `set -e`, so the inline form degrades silently to an
|
||||||
|
# empty constant. The VERSION build argument takes precedence over
|
||||||
|
# the version a build stage derives from the .git in the context.
|
||||||
|
version="$(git describe --tags --always --dirty 2>/dev/null || true)"
|
||||||
|
[ -n "$version" ] || version="unknown"
|
||||||
|
docker build --no-cache \
|
||||||
|
--build-arg VERSION="$version" \
|
||||||
|
-t "$("$SCRIPT_DIR/projectname")" .
|
||||||
}
|
}
|
||||||
|
|
||||||
main "$@"
|
main "$@"
|
||||||
|
|||||||
Reference in New Issue
Block a user