check / check (push) Failing after 2s
Keychain and Secure Enclave unlocker IDs were the creation time to the minute plus the host name, and passphrase unlocker IDs the time to the minute, so two created within one minute shared an ID, and `unlocker select`, `unlocker remove` and the selection after `unlocker add` acted on the older one. Every unlocker's ID is now its directory name, unique in its vault. `vault.ListUnlockers` returns each unlocker's metadata keyed by that name, so `unlocker list` and shell completion no longer find IDs by matching metadata. PGP unlocker IDs were `pgp-<fingerprint>`; a second PGP unlocker for one key is refused by comparing fingerprints in metadata. Model: opus-5-5
579 lines
17 KiB
Go
579 lines
17 KiB
Go
package vault
|
|
|
|
import (
|
|
"encoding/json"
|
|
"errors"
|
|
"fmt"
|
|
"log/slog"
|
|
"os"
|
|
"path/filepath"
|
|
"strings"
|
|
"time"
|
|
|
|
"filippo.io/age"
|
|
"git.eeqj.de/sneak/secret/internal/secret"
|
|
"github.com/awnumar/memguard"
|
|
"github.com/spf13/afero"
|
|
)
|
|
|
|
// Unlocker metadata type strings.
|
|
const (
|
|
unlockerTypePassphrase = "passphrase"
|
|
unlockerTypeSecureEnclave = "secure-enclave"
|
|
)
|
|
|
|
// GetCurrentUnlocker returns the current unlocker for this vault
|
|
//
|
|
//nolint:ireturn // returns one of several concrete unlocker implementations
|
|
func (v *Vault) GetCurrentUnlocker() (secret.Unlocker, error) {
|
|
secret.DebugWith("Getting current unlocker", slog.String("vault_name", v.Name))
|
|
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
secret.Debug("Failed to get vault directory for unlocker",
|
|
"error", err, "vault_name", v.Name)
|
|
|
|
return nil, err
|
|
}
|
|
|
|
currentUnlockerPath := filepath.Join(vaultDir, "current-unlocker")
|
|
|
|
// Check if the symlink exists
|
|
_, err = v.fs.Stat(currentUnlockerPath)
|
|
if err != nil {
|
|
secret.Debug("Failed to stat current unlocker symlink",
|
|
"error", err, "path", currentUnlockerPath)
|
|
|
|
return nil, fmt.Errorf("failed to read current unlocker: %w", err)
|
|
}
|
|
|
|
// Resolve the symlink to get the target directory
|
|
unlockerDir, err := v.resolveUnlockerDirectory(currentUnlockerPath)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
secret.DebugWith("Resolved unlocker directory",
|
|
slog.String("unlocker_dir", unlockerDir),
|
|
slog.String("vault_name", v.Name),
|
|
)
|
|
|
|
// Read unlocker metadata
|
|
metadata, err := v.readUnlockerMetadata(unlockerDir)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
// Create unlocker instance using direct constructors with filesystem
|
|
var unlocker secret.Unlocker
|
|
// Use metadata directly as it's already the correct type
|
|
switch metadata.Type {
|
|
case unlockerTypePassphrase:
|
|
secret.Debug("Creating passphrase unlocker instance",
|
|
"unlocker_type", metadata.Type)
|
|
|
|
passphraseUnlocker := secret.NewPassphraseUnlocker(v.fs, unlockerDir, metadata)
|
|
passphraseUnlocker.Passphrase = v.UnlockPassphrase
|
|
unlocker = passphraseUnlocker
|
|
case "pgp":
|
|
secret.Debug("Creating PGP unlocker instance", "unlocker_type", metadata.Type)
|
|
|
|
unlocker = secret.NewPGPUnlocker(v.fs, unlockerDir, metadata)
|
|
case "keychain":
|
|
secret.Debug("Creating keychain unlocker instance", "unlocker_type", metadata.Type)
|
|
|
|
unlocker = secret.NewKeychainUnlocker(v.fs, unlockerDir, metadata)
|
|
case unlockerTypeSecureEnclave:
|
|
secret.Debug("Creating secure enclave unlocker instance",
|
|
"unlocker_type", metadata.Type)
|
|
|
|
unlocker = secret.NewSecureEnclaveUnlocker(v.fs, unlockerDir, metadata)
|
|
default:
|
|
secret.Debug("Unsupported unlocker type", "type", metadata.Type)
|
|
|
|
return nil, fmt.Errorf("%w: %s", ErrUnsupportedUnlockerType, metadata.Type)
|
|
}
|
|
|
|
secret.DebugWith("Successfully created unlocker instance",
|
|
slog.String("unlocker_type", unlocker.GetType()),
|
|
slog.String("unlocker_id", unlocker.GetID()),
|
|
slog.String("vault_name", v.Name),
|
|
)
|
|
|
|
return unlocker, nil
|
|
}
|
|
|
|
// resolveUnlockerDirectory reads the current-unlocker file to get the
|
|
// unlocker directory path
|
|
// The file contains just the name of the unlocker's directory in unlockers.d
|
|
func (v *Vault) resolveUnlockerDirectory(currentUnlockerPath string) (string, error) {
|
|
secret.Debug("Reading current-unlocker file", "path", currentUnlockerPath)
|
|
|
|
unlockerNameBytes, err := afero.ReadFile(v.fs, currentUnlockerPath)
|
|
if err != nil {
|
|
secret.Debug("Failed to read current-unlocker file",
|
|
"error", err, "path", currentUnlockerPath)
|
|
|
|
return "", fmt.Errorf("failed to read current unlocker: %w", err)
|
|
}
|
|
|
|
unlockerName := strings.TrimSpace(string(unlockerNameBytes))
|
|
secret.Debug("Read unlocker name from file", "unlocker_name", unlockerName)
|
|
|
|
// Resolve to absolute path: vaultDir/unlockers.d/unlockerName
|
|
vaultDir := filepath.Dir(currentUnlockerPath)
|
|
absolutePath := filepath.Join(vaultDir, "unlockers.d", unlockerName)
|
|
|
|
secret.Debug("Resolved to absolute path", "absolute_path", absolutePath)
|
|
|
|
return absolutePath, nil
|
|
}
|
|
|
|
// findUnlockerByID finds an unlocker by its ID and returns the unlocker
|
|
// instance and its directory path. A directory that ListUnlockers skips is
|
|
// skipped here too, with the same warning. Such a directory has no ID: if
|
|
// no unlocker has the ID unlockerID but such a directory is named
|
|
// unlockerID, that directory is returned with a nil unlocker, so that
|
|
// RemoveUnlocker can remove it.
|
|
//
|
|
//nolint:ireturn // returns one of several concrete unlocker implementations
|
|
func (v *Vault) findUnlockerByID(
|
|
unlockersDir, unlockerID string,
|
|
) (secret.Unlocker, string, error) {
|
|
files, err := afero.ReadDir(v.fs, unlockersDir)
|
|
if err != nil {
|
|
return nil, "", fmt.Errorf("failed to read unlockers directory: %w", err)
|
|
}
|
|
|
|
skippedDirPath := ""
|
|
|
|
for _, file := range files {
|
|
if !file.IsDir() {
|
|
continue
|
|
}
|
|
|
|
unlockerDirPath := filepath.Join(unlockersDir, file.Name())
|
|
|
|
metadata, ok := v.readUnlockerMetadataOrWarn(unlockersDir, file.Name())
|
|
if !ok {
|
|
if file.Name() == unlockerID {
|
|
skippedDirPath = unlockerDirPath
|
|
}
|
|
|
|
continue
|
|
}
|
|
|
|
// Create the appropriate unlocker instance
|
|
var tempUnlocker secret.Unlocker
|
|
|
|
switch metadata.Type {
|
|
case unlockerTypePassphrase:
|
|
tempUnlocker = secret.NewPassphraseUnlocker(v.fs, unlockerDirPath, metadata)
|
|
case "pgp":
|
|
tempUnlocker = secret.NewPGPUnlocker(v.fs, unlockerDirPath, metadata)
|
|
case "keychain":
|
|
tempUnlocker = secret.NewKeychainUnlocker(v.fs, unlockerDirPath, metadata)
|
|
case unlockerTypeSecureEnclave:
|
|
tempUnlocker = secret.NewSecureEnclaveUnlocker(v.fs, unlockerDirPath, metadata)
|
|
default:
|
|
continue
|
|
}
|
|
|
|
// Check if this unlocker's ID matches
|
|
if tempUnlocker.GetID() == unlockerID {
|
|
return tempUnlocker, unlockerDirPath, nil
|
|
}
|
|
}
|
|
|
|
return nil, skippedDirPath, nil
|
|
}
|
|
|
|
// ListUnlockers returns the metadata of each unlocker of this vault, keyed
|
|
// by the unlocker's ID, the name of its directory in unlockers.d
|
|
func (v *Vault) ListUnlockers() (map[string]UnlockerMetadata, error) {
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
unlockersDir := filepath.Join(vaultDir, "unlockers.d")
|
|
|
|
// Check if unlockers directory exists
|
|
exists, err := afero.DirExists(v.fs, unlockersDir)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to check if unlockers directory exists: %w", err)
|
|
}
|
|
|
|
if !exists {
|
|
return map[string]UnlockerMetadata{}, nil
|
|
}
|
|
|
|
// List directories in unlockers.d
|
|
files, err := afero.ReadDir(v.fs, unlockersDir)
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to read unlockers directory: %w", err)
|
|
}
|
|
|
|
unlockers := map[string]UnlockerMetadata{}
|
|
|
|
for _, file := range files {
|
|
if !file.IsDir() {
|
|
continue
|
|
}
|
|
|
|
metadata, ok := v.readUnlockerMetadataOrWarn(unlockersDir, file.Name())
|
|
if ok {
|
|
unlockers[file.Name()] = metadata
|
|
}
|
|
}
|
|
|
|
return unlockers, nil
|
|
}
|
|
|
|
// readUnlockerMetadataOrWarn reads the metadata of the unlocker directory
|
|
// name in unlockersDir. If the metadata file cannot be checked for, is
|
|
// missing, or cannot be read or parsed, it warns, naming the directory,
|
|
// and returns false: the caller skips that directory.
|
|
func (v *Vault) readUnlockerMetadataOrWarn(
|
|
unlockersDir, name string,
|
|
) (UnlockerMetadata, bool) {
|
|
metadataPath := filepath.Join(unlockersDir, name, "unlocker-metadata.json")
|
|
|
|
var metadata UnlockerMetadata
|
|
|
|
exists, err := afero.Exists(v.fs, metadataPath)
|
|
if err != nil {
|
|
secret.Warn("Skipping unlocker directory whose metadata file cannot be checked",
|
|
"directory", name, "error", err)
|
|
|
|
return metadata, false
|
|
}
|
|
|
|
if !exists {
|
|
secret.Warn("Skipping unlocker directory with missing metadata file",
|
|
"directory", name)
|
|
|
|
return metadata, false
|
|
}
|
|
|
|
metadataBytes, err := afero.ReadFile(v.fs, metadataPath)
|
|
if err != nil {
|
|
secret.Warn("Skipping unlocker directory with unreadable metadata file",
|
|
"directory", name, "error", err)
|
|
|
|
return metadata, false
|
|
}
|
|
|
|
err = json.Unmarshal(metadataBytes, &metadata)
|
|
if err != nil {
|
|
secret.Warn("Skipping unlocker directory with corrupt metadata file",
|
|
"directory", name, "error", err)
|
|
|
|
return metadata, false
|
|
}
|
|
|
|
return metadata, true
|
|
}
|
|
|
|
// HasUnlocker reports whether RemoveUnlocker finds something to remove by
|
|
// the ID unlockerID: an unlocker with that ID, or an unlocker directory of
|
|
// that name that ListUnlockers skips.
|
|
func (v *Vault) HasUnlocker(unlockerID string) (bool, error) {
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
|
|
_, unlockerDir, err := v.findUnlockerByID(
|
|
filepath.Join(vaultDir, "unlockers.d"), unlockerID)
|
|
if err != nil {
|
|
return false, err
|
|
}
|
|
|
|
return unlockerDir != "", nil
|
|
}
|
|
|
|
// RemoveUnlocker removes an unlocker from this vault. An unlocker
|
|
// directory that ListUnlockers skips is removed by its directory name; its
|
|
// type is unknown, so only the directory is removed.
|
|
func (v *Vault) RemoveUnlocker(unlockerID string) error {
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Find the unlocker directory and create the unlocker instance
|
|
unlockersDir := filepath.Join(vaultDir, "unlockers.d")
|
|
|
|
// Find the unlocker by ID
|
|
unlocker, unlockerDir, err := v.findUnlockerByID(unlockersDir, unlockerID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
if unlockerDir == "" {
|
|
return fmt.Errorf("unlocker with ID %s %w", unlockerID, ErrUnlockerNotFound)
|
|
}
|
|
|
|
if unlocker == nil {
|
|
return secret.RemoveDirAtomic(v.fs, unlockerDir)
|
|
}
|
|
|
|
// Use the unlocker's Remove method
|
|
return unlocker.Remove()
|
|
}
|
|
|
|
// SelectUnlocker selects an unlocker as current for this vault
|
|
func (v *Vault) SelectUnlocker(unlockerID string) error {
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// Find the unlocker directory by ID
|
|
unlockersDir := filepath.Join(vaultDir, "unlockers.d")
|
|
|
|
// Find the unlocker by ID
|
|
unlocker, targetUnlockerDir, err := v.findUnlockerByID(unlockersDir, unlockerID)
|
|
if err != nil {
|
|
return err
|
|
}
|
|
|
|
// A directory found without an unlocker is one ListUnlockers skips; it
|
|
// cannot be selected.
|
|
if unlocker == nil {
|
|
return fmt.Errorf("unlocker with ID %s %w", unlockerID, ErrUnlockerNotFound)
|
|
}
|
|
|
|
// Create or replace the current-unlocker file with just the unlocker
|
|
// name. It is replaced in one rename, so it never goes missing.
|
|
currentUnlockerPath := filepath.Join(vaultDir, "current-unlocker")
|
|
|
|
// Get just the unlocker name (basename of the directory)
|
|
unlockerName := filepath.Base(targetUnlockerDir)
|
|
|
|
secret.Debug("Writing current-unlocker file", "unlocker_name", unlockerName)
|
|
|
|
err = secret.WriteFileAtomic(v.fs, currentUnlockerPath, []byte(unlockerName))
|
|
if err != nil {
|
|
return fmt.Errorf("failed to create current-unlocker file: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|
|
|
|
// CreatePassphraseUnlocker creates a new passphrase-protected unlocker in a
|
|
// directory of its own, makes it the current unlocker, and only then removes
|
|
// the vault's other passphrase unlockers: a vault keeps one. A crash at any
|
|
// point leaves a complete current unlocker, the old one or the new.
|
|
// The passphrase must be provided as a LockedBuffer for security
|
|
func (v *Vault) CreatePassphraseUnlocker(
|
|
passphrase *memguard.LockedBuffer,
|
|
) (*secret.PassphraseUnlocker, error) {
|
|
vaultDir, err := v.GetDirectory()
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to get vault directory: %w", err)
|
|
}
|
|
|
|
// We need to get the long-term key (either from memory if unlocked, or
|
|
// derive it). Getting it before anything is written means failing to
|
|
// get it changes nothing.
|
|
ltIdentity, err := v.GetOrDeriveLongTermKey()
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to get long-term key: %w", err)
|
|
}
|
|
|
|
unlockersDir := filepath.Join(vaultDir, "unlockers.d")
|
|
|
|
// The passphrase unlockers the new one replaces
|
|
oldDirs, err := v.passphraseUnlockerDirs(unlockersDir)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
unlocker, err := writePassphraseUnlocker(v.fs, vaultDir, ltIdentity, passphrase)
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
for _, oldDir := range oldDirs {
|
|
err = secret.RemoveDirAtomic(v.fs, oldDir)
|
|
if err != nil {
|
|
return nil, fmt.Errorf(
|
|
"created and selected the new passphrase unlocker: %w", err)
|
|
}
|
|
}
|
|
|
|
return unlocker, nil
|
|
}
|
|
|
|
// writePassphraseUnlocker writes a new passphrase unlocker of the long-term
|
|
// key ltIdentity into the vault directory vaultDir, in a directory of its own,
|
|
// and makes it the vault's current unlocker.
|
|
func writePassphraseUnlocker(
|
|
fs afero.Fs, vaultDir string, ltIdentity *age.X25519Identity,
|
|
passphrase *memguard.LockedBuffer,
|
|
) (*secret.PassphraseUnlocker, error) {
|
|
createdAt := time.Now()
|
|
unlockerDir := filepath.Join(vaultDir, "unlockers.d", unlockerTypePassphrase+"-"+
|
|
createdAt.UTC().Format(secret.UnlockerTimeFormat))
|
|
|
|
// Generate new age keypair for unlocker
|
|
unlockerIdentity, err := age.GenerateX25519Identity()
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to generate unlocker: %w", err)
|
|
}
|
|
|
|
// Encrypt long-term private key to this unlocker
|
|
ltPrivKeyBuffer := secret.IdentityToLockedBuffer(ltIdentity)
|
|
defer ltPrivKeyBuffer.Destroy()
|
|
|
|
encryptedLtPrivKey, err := secret.EncryptToRecipient(ltPrivKeyBuffer,
|
|
unlockerIdentity.Recipient())
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to encrypt long-term private key: %w", err)
|
|
}
|
|
|
|
metadata := UnlockerMetadata{
|
|
Type: unlockerTypePassphrase,
|
|
CreatedAt: createdAt,
|
|
Flags: []string{},
|
|
}
|
|
|
|
metadataBytes, err := json.MarshalIndent(metadata, "", " ")
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to marshal metadata: %w", err)
|
|
}
|
|
|
|
// Write the unlocker's files, the metadata last
|
|
err = secret.WriteDir(fs, unlockerDir, func(dir string) error {
|
|
return writeUnlockerFiles(fs, dir, unlockerIdentity, passphrase,
|
|
encryptedLtPrivKey, metadataBytes)
|
|
})
|
|
if err != nil {
|
|
return nil, err
|
|
}
|
|
|
|
// Make the new unlocker the current one
|
|
currentUnlockerPath := filepath.Join(vaultDir, "current-unlocker")
|
|
|
|
err = secret.WriteFileAtomic(fs, currentUnlockerPath,
|
|
[]byte(filepath.Base(unlockerDir)))
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to select new unlocker: %w", err)
|
|
}
|
|
|
|
return secret.NewPassphraseUnlocker(fs, unlockerDir, metadata), nil
|
|
}
|
|
|
|
// passphraseUnlockerDirs returns the directories in unlockersDir that hold
|
|
// passphrase unlockers. A directory ListUnlockers skips is left out, with the
|
|
// same warning.
|
|
func (v *Vault) passphraseUnlockerDirs(unlockersDir string) ([]string, error) {
|
|
files, err := afero.ReadDir(v.fs, unlockersDir)
|
|
if errors.Is(err, os.ErrNotExist) {
|
|
return nil, nil
|
|
}
|
|
|
|
if err != nil {
|
|
return nil, fmt.Errorf("failed to read unlockers directory: %w", err)
|
|
}
|
|
|
|
var dirs []string
|
|
|
|
for _, file := range files {
|
|
if !file.IsDir() {
|
|
continue
|
|
}
|
|
|
|
metadata, ok := v.readUnlockerMetadataOrWarn(unlockersDir, file.Name())
|
|
if ok && metadata.Type == unlockerTypePassphrase {
|
|
dirs = append(dirs, filepath.Join(unlockersDir, file.Name()))
|
|
}
|
|
}
|
|
|
|
return dirs, nil
|
|
}
|
|
|
|
// readUnlockerMetadata reads and parses the unlocker-metadata.json file in
|
|
// the given unlocker directory.
|
|
func (v *Vault) readUnlockerMetadata(unlockerDir string) (UnlockerMetadata, error) {
|
|
metadataPath := filepath.Join(unlockerDir, "unlocker-metadata.json")
|
|
secret.Debug("Reading unlocker metadata", "path", metadataPath)
|
|
|
|
var metadata UnlockerMetadata
|
|
|
|
metadataBytes, err := afero.ReadFile(v.fs, metadataPath)
|
|
if err != nil {
|
|
secret.Debug("Failed to read unlocker metadata", "error", err, "path", metadataPath)
|
|
|
|
return metadata, fmt.Errorf("failed to read unlocker metadata: %w", err)
|
|
}
|
|
|
|
err = json.Unmarshal(metadataBytes, &metadata)
|
|
if err != nil {
|
|
secret.Debug("Failed to parse unlocker metadata", "error", err, "path", metadataPath)
|
|
|
|
return metadata, fmt.Errorf("failed to parse unlocker metadata: %w", err)
|
|
}
|
|
|
|
secret.DebugWith("Parsed unlocker metadata",
|
|
slog.String("unlocker_type", metadata.Type),
|
|
slog.Time("created_at", metadata.CreatedAt),
|
|
slog.Any("flags", metadata.Flags),
|
|
)
|
|
|
|
return metadata, nil
|
|
}
|
|
|
|
// writeUnlockerFiles writes the files of a passphrase unlocker into
|
|
// unlockerDir: its public key, its passphrase-encrypted private key, the
|
|
// long-term private key encrypted to it, and its metadata, last.
|
|
func writeUnlockerFiles(
|
|
fs afero.Fs,
|
|
unlockerDir string,
|
|
unlockerIdentity *age.X25519Identity,
|
|
passphrase *memguard.LockedBuffer,
|
|
encryptedLtPrivKey, metadataBytes []byte,
|
|
) error {
|
|
// Write public key
|
|
pubKeyPath := filepath.Join(unlockerDir, "pub.age")
|
|
|
|
err := secret.WriteFileAtomic(fs, pubKeyPath,
|
|
[]byte(unlockerIdentity.Recipient().String()))
|
|
if err != nil {
|
|
return fmt.Errorf("failed to write unlocker public key: %w", err)
|
|
}
|
|
|
|
// Encrypt private key with passphrase
|
|
privKeyBuffer := secret.IdentityToLockedBuffer(unlockerIdentity)
|
|
defer privKeyBuffer.Destroy()
|
|
|
|
encryptedPrivKey, err := secret.EncryptWithPassphrase(privKeyBuffer, passphrase)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to encrypt unlocker private key: %w", err)
|
|
}
|
|
|
|
// Write encrypted private key
|
|
privKeyPath := filepath.Join(unlockerDir, "priv.age")
|
|
|
|
err = secret.WriteFileAtomic(fs, privKeyPath, encryptedPrivKey)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to write encrypted unlocker private key: %w", err)
|
|
}
|
|
|
|
err = secret.WriteFileAtomic(fs,
|
|
filepath.Join(unlockerDir, "longterm.age"), encryptedLtPrivKey)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to write encrypted long-term private key: %w", err)
|
|
}
|
|
|
|
err = secret.WriteFileAtomic(fs,
|
|
filepath.Join(unlockerDir, "unlocker-metadata.json"), metadataBytes)
|
|
if err != nil {
|
|
return fmt.Errorf("failed to write unlocker metadata: %w", err)
|
|
}
|
|
|
|
return nil
|
|
}
|