Files
s390-tools/rust/pvsecret/src/cmd/list.rs
Steffen Eiden 93216d916c rust/pv*: Support longer secret lists
Make use of the enhanced list secrets UAPI for the uvdevice in the latest kernel
version. This allows fetching secret lists with more than 85 entries via
reserving more userspace memory in the IOCTL argument.

While at it, move the errno readout next to the ioctl-syscall.

Acked-by: Marc Hartmayer <marc@linux.ibm.com>
Reviewed-by: Christoph Schlameuss <schlameuss@linux.ibm.com>
Signed-off-by: Steffen Eiden <seiden@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
2024-12-20 13:01:15 +01:00

61 lines
1.9 KiB
Rust

// SPDX-License-Identifier: MIT
//
// Copyright IBM Corp. 2023
use std::io::ErrorKind;
use crate::cli::{ListSecretOpt, ListSecretOutputType};
use anyhow::{Context, Error, Result};
use log::{info, warn};
use pv::uv::{ListCmd, SecretList, UvDevice};
use utils::{get_writer_from_cli_file_arg, STDOUT};
const SECRET_LIST_BUF_SIZE: usize = 4;
/// Do a List Secrets UVC
pub fn list_uvc(uv: &UvDevice) -> Result<SecretList> {
let mut cmd = ListCmd::with_pages(SECRET_LIST_BUF_SIZE);
let more_data = match uv.send_cmd(&mut cmd) {
Ok(v) => Ok(v),
Err(pv::PvCoreError::Io(e)) if e.kind() == ErrorKind::InvalidInput => {
info!("Uvdevice does not suport longer list. Fallback to one page list.");
cmd = ListCmd::default();
uv.send_cmd(&mut cmd)
}
Err(e) => Err(e),
}?
.more_data();
if more_data {
warn!("The secret list contains more data but the uvdevice cannot show all.");
}
cmd.try_into().map_err(Error::new)
}
/// Do a List Secrets UVC and output the list in the requested format
pub fn list(opt: &ListSecretOpt) -> Result<()> {
let uv = UvDevice::open()?;
let secret_list = list_uvc(&uv)?;
let mut wr_out = get_writer_from_cli_file_arg(&opt.output)?;
match &opt.format {
ListSecretOutputType::Human => {
write!(wr_out, "{secret_list}").context("Cannot generate output")?
}
ListSecretOutputType::Yaml => write!(wr_out, "{}", serde_yaml::to_string(&secret_list)?)
.context("Cannot generate yaml output")?,
ListSecretOutputType::Bin => secret_list
.encode(&mut wr_out)
.context("Cannot encode secret list")?,
}
wr_out.flush()?;
if opt.output != STDOUT {
warn!(
"Successfully wrote the list of secrets to '{}'",
&opt.output
);
}
Ok(())
}