/* Copyright 2022-2023 CAcert Inc. SPDX-License-Identifier: Apache-2.0 Licensed under the Apache License, Version 2.0 (the "License"); you may not use this file except in compliance with the License. You may obtain a copy of the License at http://www.apache.org/licenses/LICENSE-2.0 Unless required by applicable law or agreed to in writing, software distributed under the License is distributed on an "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. See the License for the specific language governing permissions and limitations under the License. */ package config import ( "fmt" "io" "os" "time" "gopkg.in/yaml.v3" ) const ( defaultSerialTimeout = 5 * time.Second defaultHealthInterval = 30 * time.Second defaultHealthStart = 2 * time.Second defaultFetchCRLInterval = 5 * time.Minute defaultFetchCRLStart = 5 * time.Minute defaultResponseAnnounceTimeout = 30 * time.Second defaultResponseDataTimeout = 2 * time.Second defaultFilesDirectory = "public" defaultCommandChannelCapacity = 100 defaultDatabaseConnMaxLiveTime = 3 * time.Minute defaultDatabaseMaxOpenConns = 10 defaultDatabaseMaxIdleConns = 10 ) type SettingsError struct { msg string } func (se SettingsError) Error() string { return fmt.Sprintf("invalid Settings %s", se.msg) } type Serial struct { Device string `yaml:"device"` Baud int `yaml:"baud"` Timeout time.Duration `yaml:"timeout"` } type Database struct { DSN string `yaml:"dsn"` ConnMaxLiveTime time.Duration `yaml:"conn-max-live-time"` MaxOpenConns int `yaml:"max-open-conns"` MaxIdleConns int `yaml:"max-idle-conns"` } type ClientConfig struct { Serial Serial `yaml:"serial"` HealthInterval time.Duration `yaml:"health-interval"` HealthStart time.Duration `yaml:"health-start"` FetchCRLStart time.Duration `yaml:"fetch-crl-start"` FetchCRLInterval time.Duration `yaml:"fetch-crl-interval"` ResponseAnnounceTimeout time.Duration `yaml:"response-announce-timeout"` ResponseDataTimeout time.Duration `yaml:"response-data-timeout"` PublicCRLDirectory string `yaml:"public-crl-directory"` PublicCertificateDirectory string `yaml:"public-certificate-directory"` CommandChannelCapacity int `yaml:"command-channel-capacity"` Database Database `yaml:"database"` } func (c *ClientConfig) UnmarshalYAML(n *yaml.Node) error { data := struct { Serial Serial `yaml:"serial"` HealthInterval time.Duration `yaml:"health-interval"` HealthStart time.Duration `yaml:"health-start"` FetchCRLStart time.Duration `yaml:"fetch-crl-start"` FetchCRLInterval time.Duration `yaml:"fetch-crl-interval"` ResponseAnnounceTimeout time.Duration `yaml:"response-announce-timeout"` ResponseDataTimeout time.Duration `yaml:"response-data-timeout"` PublicCRLDirectory string `yaml:"public-crl-directory"` PublicCertificateDirectory string `yaml:"public-certificate-directory"` CommandChannelCapacity int `yaml:"command-channel-capacity"` Database Database `yaml:"database"` }{} err := n.Decode(&data) if err != nil { return fmt.Errorf("could not decode YAML: %w", err) } if err := checkSerialConfig(&data.Serial); err != nil { return err } c.Serial = data.Serial if data.HealthInterval == 0 { data.HealthInterval = defaultHealthInterval } c.HealthInterval = data.HealthInterval if data.HealthStart == 0 { data.HealthStart = defaultHealthStart } c.HealthStart = data.HealthStart if data.FetchCRLInterval == 0 { data.FetchCRLInterval = defaultFetchCRLInterval } c.FetchCRLInterval = data.FetchCRLInterval if data.FetchCRLStart == 0 { data.FetchCRLStart = defaultFetchCRLStart } c.FetchCRLStart = data.FetchCRLStart if data.ResponseAnnounceTimeout == 0 { data.ResponseAnnounceTimeout = defaultResponseAnnounceTimeout } c.ResponseAnnounceTimeout = data.ResponseAnnounceTimeout if data.ResponseDataTimeout == 0 { data.ResponseDataTimeout = defaultResponseDataTimeout } c.ResponseDataTimeout = data.ResponseDataTimeout if data.PublicCRLDirectory == "" { data.PublicCRLDirectory = defaultFilesDirectory } c.PublicCRLDirectory = data.PublicCRLDirectory if data.PublicCertificateDirectory == "" { data.PublicCertificateDirectory = defaultFilesDirectory } if data.CommandChannelCapacity == 0 { data.CommandChannelCapacity = defaultCommandChannelCapacity } c.CommandChannelCapacity = data.CommandChannelCapacity c.PublicCertificateDirectory = data.PublicCRLDirectory if err := checkDatabaseConfig(&data.Database); err != nil { return err } c.Database = data.Database c.Database = data.Database return nil } func checkDatabaseConfig(d *Database) error { if d.DSN == "" { return SettingsError{"you must specify a database 'dsn'"} } if d.ConnMaxLiveTime == 0 { d.ConnMaxLiveTime = defaultDatabaseConnMaxLiveTime } if d.MaxOpenConns == 0 { d.MaxOpenConns = defaultDatabaseMaxOpenConns } if d.MaxIdleConns == 0 { d.MaxIdleConns = defaultDatabaseMaxIdleConns } return nil } func checkSerialConfig(s *Serial) error { if s.Device == "" { return SettingsError{"you must specify a serial 'device'"} } if s.Baud == 0 { s.Baud = 115200 } if s.Timeout == 0 { s.Timeout = defaultSerialTimeout } return nil } func New(clientConfigFile string) (*ClientConfig, error) { configFile, err := os.Open(clientConfigFile) if err != nil { return nil, fmt.Errorf("could not open signer client configuration file %s: %w", clientConfigFile, err) } defer func() { _ = configFile.Close() }() clientConfig, err := LoadConfiguration(configFile) if err != nil { return nil, fmt.Errorf("could not load client configuration from %s: %w", clientConfigFile, err) } return clientConfig, nil } func LoadConfiguration(r io.Reader) (*ClientConfig, error) { var config *ClientConfig decoder := yaml.NewDecoder(r) err := decoder.Decode(&config) if err != nil { return nil, fmt.Errorf("could not parse YAML configuration: %w", err) } return config, nil }