Method: Chef::Provider::Directory#define_resource_requirements

Defined in:
lib/chef/provider/directory.rb

#define_resource_requirementsObject



41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
# File 'lib/chef/provider/directory.rb', line 41

def define_resource_requirements
  # deep inside FAC we have to assert requirements, so call FACs hook to set that up
  access_controls.define_resource_requirements

  requirements.assert(:create) do |a|
    # Make sure the parent dir exists, or else fail.
    # for why run, print a message explaining the potential error.
    parent_directory = ::File.dirname(new_resource.path)
    a.assertion do
      if new_resource.recursive
        does_parent_exist = lambda do |base_dir|
          base_dir = ::File.dirname(base_dir)
          if ::TargetIO::File.exist?(base_dir)
            ::TargetIO::File.directory?(base_dir)
          else
            does_parent_exist.call(base_dir)
          end
        end
        does_parent_exist.call(new_resource.path)
      else
        ::TargetIO::File.directory?(parent_directory)
      end
    end
    a.failure_message(Chef::Exceptions::EnclosingDirectoryDoesNotExist, "Parent directory #{parent_directory} does not exist, cannot create #{new_resource.path}")
    a.whyrun("Assuming directory #{parent_directory} would have been created")
  end

  requirements.assert(:create) do |a|
    a.assertion do
      if ::TargetIO::File.exist?(new_resource.path)
        ::TargetIO::File.directory?(new_resource.path)
      else
        true
      end
    end
    a.failure_message(Chef::Exceptions::FileTypeMismatch, "Cannot create #{new_resource} at #{new_resource.path} because a file already exists at that path")
  end

  requirements.assert(:create) do |a|
    parent_directory = ::File.dirname(new_resource.path)
    a.assertion do
      if new_resource.recursive
        # find the lowest-level directory in new_resource.path that already exists
        # make sure we have write permissions to that directory
        is_parent_writable = lambda do |base_dir|
          base_dir = ::File.dirname(base_dir)
          if ::TargetIO::File.exist?(base_dir)
            if Chef::FileAccessControl.writable?(base_dir)
              true
            elsif Chef::Util::PathHelper.is_sip_path?(base_dir, node)
              Chef::Util::PathHelper.writable_sip_path?(base_dir)
            else
              false
            end
          else
            is_parent_writable.call(base_dir)
          end
        end
        is_parent_writable.call(new_resource.path)
      else
        # in why run mode & parent directory does not exist no permissions check is required
        # If not in why run, permissions must be valid and we rely on prior assertion that dir exists
        if !whyrun_mode? || ::TargetIO::File.exist?(parent_directory)
          if Chef::FileAccessControl.writable?(parent_directory)
            true
          elsif Chef::Util::PathHelper.is_sip_path?(parent_directory, node)
            Chef::Util::PathHelper.writable_sip_path?(new_resource.path)
          else
            false
          end
        else
          true
        end
      end
    end
    a.failure_message(Chef::Exceptions::InsufficientPermissions,
      "Cannot create #{new_resource} at #{new_resource.path} due to insufficient permissions")
  end

  requirements.assert(:delete) do |a|
    a.assertion do
      if ::TargetIO::File.exist?(new_resource.path)
        ::TargetIO::File.directory?(new_resource.path) && Chef::FileAccessControl.writable?(new_resource.path)
      else
        true
      end
    end
    a.failure_message(RuntimeError, "Cannot delete #{new_resource} at #{new_resource.path}!")
    # No why-run handling here:
    #  * if we don't have permissions, this is unlikely to be changed earlier in the run
    #  * if the target is a file (not a dir), there's no reasonable path by which this would have been changed
  end
end