From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp10.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id yB/uBszR4mHGygAAgWs5BA (envelope-from ) for ; Sat, 15 Jan 2022 14:53:16 +0100 Received: from aspmx1.migadu.com ([2001:41d0:2:4a6f::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp10.migadu.com with LMTPS id EO5cO8vR4mGa/gAAG6o9tA (envelope-from ) for ; Sat, 15 Jan 2022 14:53:15 +0100 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id A7A9A29E62 for ; Sat, 15 Jan 2022 14:53:15 +0100 (CET) Received: from localhost ([::1]:42442 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1n8jUY-00085O-Sa for larch@yhetil.org; Sat, 15 Jan 2022 08:53:14 -0500 Received: from eggs.gnu.org ([209.51.188.92]:38006) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1n8jTc-00067d-Jh for guix-patches@gnu.org; Sat, 15 Jan 2022 08:52:16 -0500 Received: from debbugs.gnu.org ([209.51.188.43]:46646) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1n8jTP-0004RN-97 for guix-patches@gnu.org; Sat, 15 Jan 2022 08:52:14 -0500 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1n8jTP-0001ud-9U for guix-patches@gnu.org; Sat, 15 Jan 2022 08:52:03 -0500 X-Loop: help-debbugs@gnu.org Subject: [bug#53063] [PATCH v2 wip-harden-installer 17/18] installer: Turn passwords into opaque records. Resent-From: Josselin Poiret Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Sat, 15 Jan 2022 13:52:03 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 53063 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Mathieu Othacehe Cc: 53063@debbugs.gnu.org, ludo@gnu.org, Josselin Poiret Received: via spool by 53063-submit@debbugs.gnu.org id=B53063.16422546757245 (code B ref 53063); Sat, 15 Jan 2022 13:52:03 +0000 Received: (at 53063) by debbugs.gnu.org; 15 Jan 2022 13:51:15 +0000 Received: from localhost ([127.0.0.1]:39543 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1n8jSd-0001sg-8t for submit@debbugs.gnu.org; Sat, 15 Jan 2022 08:51:15 -0500 Received: from jpoiret.xyz ([206.189.101.64]:49658) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1n8jS3-0001nw-J1 for 53063@debbugs.gnu.org; Sat, 15 Jan 2022 08:50:40 -0500 Received: from authenticated-user (jpoiret.xyz [206.189.101.64]) by jpoiret.xyz (Postfix) with ESMTPA id E1B61185148; Sat, 15 Jan 2022 13:50:38 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=jpoiret.xyz; s=dkim; t=1642254639; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding: in-reply-to:in-reply-to:references:references; bh=mgahbeW99p08uqGuUoQSrqa3yRE4WTyhH8DCGFxLk5c=; b=W/p+G0xRU+ZoDEi6PIrFpUTc503oYj18Om1eD3MsQMuodjZP3LICSgR1GsWrkwCdVya6nN y61eces6/kDQhld9SZlVo6/atIchs2FH7ceAXg7pTW6SephK2MrVlJzcZ8RITKAj/QmaAl vDz4VL4WTJr+HTfS2s1iGMCW+XTkjMktmWww4HUx/JWFMLMlzo5+J5C9XazhRcaSFBCpod UfKrpmaMI1dQ1c7+wB9OQv9cj6hos20Sic7Mtitxwn6AaNxNX3xMD/7O5sRsqKAhzsnNP+ DCR4jHS/A3lunSxrZ159qYBhHhrBZ04SPW9xzymJYyCptNrXVxUiHiGhR5LjhQ== Date: Sat, 15 Jan 2022 14:50:10 +0100 Message-Id: <20220115135011.5817-18-dev@jpoiret.xyz> In-Reply-To: <20220115135011.5817-1-dev@jpoiret.xyz> References: <8735lz4xsv.fsf@gnu.org> <20220115135011.5817-1-dev@jpoiret.xyz> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Spamd-Bar: / X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" Reply-to: Josselin Poiret X-ACL-Warn: , Josselin Poiret via Guix-patches From: Josselin Poiret via Guix-patches via X-Migadu-Flow: FLOW_IN X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1642254795; h=from:from:sender:sender:reply-to:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-transfer-encoding:content-transfer-encoding:resent-cc: resent-from:resent-sender:resent-message-id:in-reply-to:in-reply-to: references:references:list-id:list-help:list-unsubscribe: list-subscribe:list-post:dkim-signature; bh=mgahbeW99p08uqGuUoQSrqa3yRE4WTyhH8DCGFxLk5c=; b=qEn7IL3y7AHMfjN2kyGHhXo2YMpdeG7isaPxjsHEMGMbsXzPrRcByn4e/xSkYvnwMfxjEY HDaeRT6qTHJLSeDYjX2JWK+5Z84Sg8W3+ndn/ZTXNpoLC05YkReSGjnT//5F7UvZ4PtaPV fkbGpfKufmEL8HF+b21PZ/qs9dEXLIUje88JjbkYPEdQHhk6FiheTk6WaedQ5xoD04WP4n 9/IHzF91F6RgLwDXILu8gvYbamkSjxz5Zmrpoou8gx4F/SjeM5KbfHiK8cXKio1FxNitH8 aIb1NV/bIOnP1w/4PqPCgiqYbTv8VDvWWKIae85nSQHF2LZFxNcslY+/1Lfj/A== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1642254795; a=rsa-sha256; cv=none; b=dibSNKvSyTcsvmtCIk2kfz2fC1avW7dIVEYa93Sk25hSThPxT7E7RuCfLgab2V+wO4cYib cO7fiog7cBUcAemd02K0ni+nJj/sUolmftMy7+x28Bjzrnl8BMHwmQ2Y6OCFQcpcKGAEH1 1J75RanxVIGm/ofiD66YsR1qRujlBqR+U9hYB1BrJhq5hLh1qrB1Oc8eNWhUMFIxNx5u7l w8gb0+6r1txjwjjnhOV3GIZ/P+AHrs6ZUQy3/kp5OmhAz3nhmnuy10jPFL7idL37b6A6A1 nrp3r6LLlVUvMolthn9eu7RAUhHyLXMdAJagLSshDQChSmwlJEAOLSU6Bz6r9A== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=jpoiret.xyz header.s=dkim header.b="W/p+G0xR"; dmarc=pass (policy=none) header.from=gnu.org; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: -3.93 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=jpoiret.xyz header.s=dkim header.b="W/p+G0xR"; dmarc=pass (policy=none) header.from=gnu.org; spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: A7A9A29E62 X-Spam-Score: -3.93 X-Migadu-Scanner: scn0.migadu.com X-TUID: RNX+TH5f2NBb * gnu/installer/user.scm (, secret?, make-secret, secret-content): Add opaque record that boxes its contents, with a custom printer that doesn't display anything. * gnu/installer/newt/user.scm (run-user-add-page, run-user-page): Box it. * gnu/installer/final.scm (create-user-database): Unbox it. --- gnu/installer/final.scm | 5 +++-- gnu/installer/newt/user.scm | 6 +++--- gnu/installer/user.scm | 18 +++++++++++++++++- 3 files changed, 23 insertions(+), 6 deletions(-) diff --git a/gnu/installer/final.scm b/gnu/installer/final.scm index 63e5073ff4..2087536502 100644 --- a/gnu/installer/final.scm +++ b/gnu/installer/final.scm @@ -85,8 +85,9 @@ (define root? (uid (if root? 0 #f)) (home-directory (user-home-directory user)) - (password (crypt (user-password user) - (salt))) + (password (crypt + (secret-content (user-password user)) + (salt))) ;; We need a string here, not a file-like, hence ;; this choice. diff --git a/gnu/installer/newt/user.scm b/gnu/installer/newt/user.scm index 97141cfe64..7c1cc2249d 100644 --- a/gnu/installer/newt/user.scm +++ b/gnu/installer/newt/user.scm @@ -143,7 +143,7 @@ (define (pad-label label) (name name) (real-name real-name) (home-directory home-directory) - (password password)) + (password (make-secret password))) (run-user-add-page #:name name #:real-name real-name #:home-directory @@ -266,7 +266,7 @@ (define (run users) (map (lambda (name real-name home password) (user (name name) (real-name real-name) (home-directory home) - (password password))) + (password (make-secret password)))) names real-names homes passwords)))))) (lambda () (destroy-form-and-pop form)))))) @@ -274,5 +274,5 @@ (define (run users) ;; Add a "root" user simply to convey the root password. (cons (user (name "root") (home-directory "/root") - (password (run-root-password-page))) + (password (make-secret (run-root-password-page)))) (run '()))) diff --git a/gnu/installer/user.scm b/gnu/installer/user.scm index 4e701e64ce..13114e9832 100644 --- a/gnu/installer/user.scm +++ b/gnu/installer/user.scm @@ -19,7 +19,14 @@ (define-module (gnu installer user) #:use-module (guix records) #:use-module (srfi srfi-1) - #:export ( + #:use-module (srfi srfi-9) + #:use-module (srfi srfi-9 gnu) + #:export ( + secret? + make-secret + secret-content + + user make-user user-name @@ -30,6 +37,15 @@ (define-module (gnu installer user) users->configuration)) +(define-record-type + (make-secret content) + secret? + (content secret-content)) +(set-record-type-printer! + + (lambda (secret port) + (format port ""))) + (define-record-type* user make-user user? -- 2.34.0