Method: Inspec::Resources::DarwinGroup#groups

Defined in:
lib/inspec/resources/groups.rb

#groupsObject



270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
# File 'lib/inspec/resources/groups.rb', line 270

def groups
  # https://apple.stackexchange.com/a/130815

  group_by_id = runmap("dscl . -list /Groups PrimaryGroupID")  { |l| name, id = l.split; [id.to_i, name] }
  userss      = runmap("dscl . -list /Users  PrimaryGroupID")  { |l| name, id = l.split; [name, id.to_i] }
  membership  = runmap("dscl . -list /Groups GroupMembership") { |l| key, *vs = l.split; [key, vs] }
  membership.default_proc = ->(h, k) { h[k] = [] }

  users_by_group = hashmap(userss.keys.group_by { |k| userss[k] }) { |k, vs| [group_by_id[k], vs] }
  users_by_group.each do |name, users|
    membership[name].concat users
  end

  group_info = inspec.command("dscacheutil -q group").stdout.split("\n\n").uniq

  regex = /^([^:]*?)\s*:\s(.*?)\s*$/
  groups = group_info.map do |data|
    inspec.parse_config(data, assignment_regex: regex).params
  end

  # Convert the `dscacheutil` groups to match `inspec.etc_group.entries`
  groups.each { |g| g["gid"] = g["gid"].to_i }
  groups.each do |g|
    users = g.delete("users") || ""
    users = users.split
    users += Array(users_by_group[g["name"]])
    g["members"] = users.sort
  end

  groups # de-dupe/merge by gid
    .group_by { |g| g["gid"] }
    .values
    .map { |subgroups|
      g = subgroups.first

      if subgroups.size != 1
        g["members"] = subgroups.map { |h| h["members"] }.flatten.uniq
      end

      g
    }
end