gmsm/smx509/root_unix.go

103 lines
2.6 KiB
Go
Raw Normal View History

2021-10-12 09:25:53 +08:00
//go:build aix || dragonfly || freebsd || (js && wasm) || linux || netbsd || openbsd || solaris
2021-02-15 20:09:49 +08:00
// +build aix dragonfly freebsd js,wasm linux netbsd openbsd solaris
package smx509
import (
2021-12-03 15:29:44 +08:00
"io/ioutil"
2021-02-15 20:09:49 +08:00
"os"
2021-12-03 15:12:27 +08:00
"path/filepath"
"strings"
2021-02-15 20:09:49 +08:00
)
const (
// certFileEnv is the environment variable which identifies where to locate
// the SSL certificate file. If set this overrides the system default.
certFileEnv = "SSL_CERT_FILE"
// certDirEnv is the environment variable which identifies which directory
// to check for SSL certificate files. If set this overrides the system default.
certDirEnv = "SSL_CERT_DIR"
)
func (c *Certificate) systemVerify(opts *VerifyOptions) (chains [][]*Certificate, err error) {
return nil, nil
}
func loadSystemRoots() (*CertPool, error) {
roots := NewCertPool()
files := certFiles
if f := os.Getenv(certFileEnv); f != "" {
files = []string{f}
}
var firstErr error
for _, file := range files {
2021-12-03 15:29:44 +08:00
data, err := ioutil.ReadFile(file)
2021-02-15 20:09:49 +08:00
if err == nil {
roots.AppendCertsFromPEM(data)
break
}
if firstErr == nil && !os.IsNotExist(err) {
firstErr = err
}
}
dirs := certDirectories
if d := os.Getenv(certDirEnv); d != "" {
2021-12-03 15:12:27 +08:00
// OpenSSL and BoringSSL both use ":" as the SSL_CERT_DIR separator.
// See:
// * https://golang.org/issue/35325
// * https://www.openssl.org/docs/man1.0.2/man1/c_rehash.html
dirs = strings.Split(d, ":")
2021-02-15 20:09:49 +08:00
}
for _, directory := range dirs {
2021-12-03 15:12:27 +08:00
fis, err := readUniqueDirectoryEntries(directory)
2021-02-15 20:09:49 +08:00
if err != nil {
if firstErr == nil && !os.IsNotExist(err) {
firstErr = err
}
continue
}
for _, fi := range fis {
2021-12-03 15:29:44 +08:00
data, err := ioutil.ReadFile(directory + "/" + fi.Name())
2021-12-03 15:12:27 +08:00
if err == nil {
roots.AppendCertsFromPEM(data)
2021-02-15 20:09:49 +08:00
}
}
}
2021-12-03 15:12:27 +08:00
if roots.len() > 0 || firstErr == nil {
2021-02-15 20:09:49 +08:00
return roots, nil
}
return nil, firstErr
}
2021-12-03 15:12:27 +08:00
2021-12-03 15:29:44 +08:00
// readUniqueDirectoryEntries is like ioutil.ReadDir but omits
2021-12-03 15:12:27 +08:00
// symlinks that point within the directory.
2021-12-03 15:29:44 +08:00
func readUniqueDirectoryEntries(dir string) ([]os.FileInfo, error) {
fis, err := ioutil.ReadDir(dir)
2021-12-03 15:12:27 +08:00
if err != nil {
return nil, err
}
2021-12-03 15:29:44 +08:00
uniq := fis[:0]
for _, fi := range fis {
if !isSameDirSymlink(fi, dir) {
uniq = append(uniq, fi)
2021-12-03 15:12:27 +08:00
}
}
return uniq, nil
}
// isSameDirSymlink reports whether fi in dir is a symlink with a
// target not containing a slash.
2021-12-03 15:29:44 +08:00
func isSameDirSymlink(fi os.FileInfo, dir string) bool {
if fi.Mode()&os.ModeSymlink == 0 {
2021-12-03 15:12:27 +08:00
return false
}
2021-12-03 15:29:44 +08:00
target, err := os.Readlink(filepath.Join(dir, fi.Name()))
2021-12-03 15:12:27 +08:00
return err == nil && !strings.Contains(target, "/")
2021-12-03 15:29:44 +08:00
}