From patchwork Tue Apr 28 15:00:23 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: pinoaffe X-Patchwork-Id: 21714 Return-Path: X-Original-To: patchwork@mira.cbaines.net Delivered-To: patchwork@mira.cbaines.net Received: by mira.cbaines.net (Postfix, from userid 113) id 8919027BBEA; Tue, 28 Apr 2020 16:04:59 +0100 (BST) X-Spam-Checker-Version: SpamAssassin 3.4.2 (2018-09-13) on mira.cbaines.net X-Spam-Level: X-Spam-Status: No, score=-2.8 required=5.0 tests=BAYES_00,DKIM_SIGNED, MAILING_LIST_MULTI,T_DKIM_INVALID,URIBL_BLOCKED autolearn=unavailable autolearn_force=no version=3.4.2 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) by mira.cbaines.net (Postfix) with ESMTP id 0F3F227BBE4 for ; Tue, 28 Apr 2020 16:04:59 +0100 (BST) Received: from localhost ([::1]:34248 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jTRn8-0005o1-0L for patchwork@mira.cbaines.net; Tue, 28 Apr 2020 11:04:58 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:49402) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1jTRm8-0005kg-MV for guix-patches@gnu.org; Tue, 28 Apr 2020 11:04:46 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.90_1) (envelope-from ) id 1jTRjU-00072M-U4 for guix-patches@gnu.org; Tue, 28 Apr 2020 11:03:56 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:57769) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1jTRjK-00071G-IE for guix-patches@gnu.org; Tue, 28 Apr 2020 11:01:08 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1jTRjK-0003Q3-G0 for guix-patches@gnu.org; Tue, 28 Apr 2020 11:01:02 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#40878] [PATCH v2] services: mpd: Allow authentication and permissions to be configured. References: <1ee4ef44362d20518fe69da7b6c37df5@airmail.cc> In-Reply-To: <1ee4ef44362d20518fe69da7b6c37df5@airmail.cc> Resent-From: pinoaffe Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Tue, 28 Apr 2020 15:01:02 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 40878 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: 40878@debbugs.gnu.org Received: via spool by 40878-submit@debbugs.gnu.org id=B40878.158808603613103 (code B ref 40878); Tue, 28 Apr 2020 15:01:02 +0000 Received: (at 40878) by debbugs.gnu.org; 28 Apr 2020 15:00:36 +0000 Received: from localhost ([127.0.0.1]:41082 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jTRiu-0003PG-3T for submit@debbugs.gnu.org; Tue, 28 Apr 2020 11:00:36 -0400 Received: from mail.cock.li ([37.120.193.124]:53126) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1jTRir-0003P1-4S for 40878@debbugs.gnu.org; Tue, 28 Apr 2020 11:00:34 -0400 Date: Tue, 28 Apr 2020 17:00:23 +0200 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=airmail.cc; s=mail; t=1588086026; bh=KJKUIjeQkKGxIoZfDFg4N8mF8/Mc9Ku+kbKfgTMa9XE=; h=Date:From:To:Subject:From; b=WAakHi3NGNRbgpjTjEIN8Q9vT6hO79DfDRig2XGebbsYBgtR4EN+Avxx9KEeQLuF9 crD5mBk3YyyVSKGibe6N+SbWMgAvWUb4xh4C5amuIoOLP3olXMWXaO2KYPeiKT0uWm seMXa7WmgLHTFPUipGV/jwoz3Wimk0UG5UmR6rgQF87acbCf4iHdVh0R6u0Sa8wvWw TM3iNtleU+NmIWUI0sCZD5SpyiTA/WHYTr9aLU7pZbGG32w6fUuwVzrtFd1XZb5Qt8 yL9Aghj5Aaw3bG6n9CY6YGSaEBJu+Rvb8zMrj3mvAAoTt1pX8YC4jJRnLd8QyO2M6J SEkwQn2QRoh/Q== From: pinoaffe Message-ID: <20200428170023.3304924a@airmail.cc> X-Mailer: Claws Mail 3.17.5 (GTK+ 2.24.32; x86_64-unknown-linux-gnu) MIME-Version: 1.0 X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-Received-From: 209.51.188.43 X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+patchwork=mira.cbaines.net@gnu.org Sender: "Guix-patches" X-getmail-retrieved-from-mailbox: Patches * gnu/services/audio.scm (mpd-credential): New public variable. * gnu/services/audio.scm (mpd-configuration): Add credentials and permissions. --- doc/guix.texi | 26 ++++++++++++++ gnu/services/audio.scm | 79 ++++++++++++++++++++++++++++++------------ 2 files changed, 83 insertions(+), 22 deletions(-) diff --git a/doc/guix.texi b/doc/guix.texi index 6613a4af13..6a5038fd37 100644 --- a/doc/guix.texi +++ b/doc/guix.texi @@ -23271,6 +23271,32 @@ an absolute path can be specified here. @item @code{outputs} (default: @code{"(list (mpd-output))"}) The audio outputs that MPD can use. By default this is a single output using pulseaudio. +@item @code{default-permissions} (default: @code{'(read add control admin)}) +The permissions a user that connected to the mpd server without a password should enjoy. +Should be a subset of @code{'(read add control admin)}. + +@item @code{credentials} (default: @code{'()}) +The list of credentials one can use to sign in to mpd and gain extra permissions. By +default this is an empty list. + +@end table +@end deftp + +@deftp {Data Type} mpd-credential +Data type representing an @command{mpd} password/permissions pair. + +@table @asis +@item @code{password} (default: @code{""}) +The password used to authenticate. The password may not contain "@". +Warning: due to limitations of the mpd configuration system, the generated mpd config +(which is stored in the guix store and is readable to all users) will include a +plaintext copy of the provided password(s). + +@item @code{permissions} (default: @code{'()}) +The permissions one gains after authenticating to the server using @code{password}. +This should be a subset of @code{'(read add control admin)}, as in +@code{default-permissions}. + @end table @end deftp diff --git a/gnu/services/audio.scm b/gnu/services/audio.scm index 345d8225b2..9a6dc8db94 100644 --- a/gnu/services/audio.scm +++ b/gnu/services/audio.scm @@ -26,6 +26,8 @@ #:use-module (ice-9 match) #:export (mpd-output mpd-output? + mpd-credential + mpd-credential? mpd-configuration mpd-configuration? mpd-service-type)) @@ -36,6 +38,16 @@ ;;; ;;; Code: +(define-record-type* + mpd-credential make-mpd-credential + mpd-credential? + (password mpd-credential-password + ;; valid: any string that does not contain #\@ + (default "")) + (permissions mpd-credential-permissions + ;; valid: any subset of read, add, control and admin + (default '()))) + (define-record-type* mpd-output make-mpd-output mpd-output? @@ -58,24 +70,41 @@ (define-record-type* mpd-configuration make-mpd-configuration mpd-configuration? - (user mpd-configuration-user - (default "mpd")) - (music-dir mpd-configuration-music-dir - (default "~/Music")) - (playlist-dir mpd-configuration-playlist-dir - (default "~/.mpd/playlists")) - (db-file mpd-configuration-db-file - (default "~/.mpd/tag_cache")) - (state-file mpd-configuration-state-file - (default "~/.mpd/state")) - (sticker-file mpd-configuration-sticker-file - (default "~/.mpd/sticker.sql")) - (port mpd-configuration-port - (default "6600")) - (address mpd-configuration-address - (default "any")) - (outputs mpd-configuration-outputs - (default (list (mpd-output))))) + (user mpd-configuration-user + (default "mpd")) + (music-dir mpd-configuration-music-dir + (default "~/Music")) + (playlist-dir mpd-configuration-playlist-dir + (default "~/.mpd/playlists")) + (db-file mpd-configuration-db-file + (default "~/.mpd/tag_cache")) + (state-file mpd-configuration-state-file + (default "~/.mpd/state")) + (sticker-file mpd-configuration-sticker-file + (default "~/.mpd/sticker.sql")) + (port mpd-configuration-port + (default "6600")) + (address mpd-configuration-address + (default "any")) + (credentials mpd-configuration-credentials + (default '())) + (default-permissions mpd-configuration-default-permissions + (default '(read add control admin))) + (outputs mpd-configuration-outputs + (default (list (mpd-output))))) + +(define (mpd-permissions->string permissions) + (string-join (map symbol->string + permissions) + ",")) + +(define (mpd-credential->string credential) + "Convert the USER of type to a configuration file snippet." + (format #f + "password \"~a@~a\"\n" + (mpd-credential-password credential) + (mpd-permissions->string + (mpd-credential-permissions credential)))) (define (mpd-output->string output) "Convert the OUTPUT of type to a configuration file snippet." @@ -110,8 +139,14 @@ audio_output { (apply mixed-text-file "mpd.conf" "pid_file \"" (mpd-file-name config "pid") "\"\n" + "default_permissions \"" + (mpd-permissions->string + (mpd-configuration-default-permissions config)) + "\"\n" (append (map mpd-output->string (mpd-configuration-outputs config)) + (map mpd-credential->string + (mpd-configuration-credentials config)) (map (match-lambda ((config-name config-val) (string-append config-name " \"" (config-val config) "\"\n"))) @@ -143,10 +178,10 @@ audio_output { #:environment-variables ;; Required to detect PulseAudio when run under a user account. '(#$(string-append - "XDG_RUNTIME_DIR=/run/user/" - (number->string - (passwd:uid - (getpwnam (mpd-configuration-user config)))))) + "XDG_RUNTIME_DIR=/run/user/" + (number->string + (passwd:uid + (getpwnam (mpd-configuration-user config)))))) #:log-file #$(mpd-file-name config "log"))) (stop #~(make-kill-destructor))))