/mandos/release

To get this branch, use:
bzr branch http://bzr.recompile.se/loggerhead/mandos/release

« back to all changes in this revision

Viewing changes to mandos-ctl

  • Committer: Teddy Hogeborn
  • Date: 2019-03-07 21:37:10 UTC
  • mto: (237.7.594 trunk)
  • mto: This revision was merged to the branch mainline in revision 382.
  • Revision ID: teddy@recompile.se-20190307213710-brbbpkpqxcq8e444
mandos-ctl.xml: Clarify the conflicting nature of some options

* mandos-ctl.xml (SYNOPSIS): Show --start-checker and --stop-checker
                             as mutually exclusive.  Show --remove as
                             incompatible with everything except
                             --deny.

Show diffs side-by-side

added added

removed removed

Lines of Context:
42
42
import json
43
43
import unittest
44
44
import logging
 
45
import io
 
46
import tempfile
45
47
 
46
48
import dbus
47
49
 
278
280
        commands which want to operate on all clients at the same time
279
281
        can override this run() method instead."""
280
282
        self.mandos = mandos
281
 
        for client in clients:
282
 
            self.run_on_one_client(client)
 
283
        for client, properties in clients.items():
 
284
            self.run_on_one_client(client, properties)
283
285
 
284
286
class PrintCmd(Command):
285
287
    """Abstract class for commands printing client details"""
295
297
 
296
298
class PropertyCmd(Command):
297
299
    """Abstract class for Actions for setting one client property"""
298
 
    def run_on_one_client(self, client):
 
300
    def run_on_one_client(self, client, properties):
299
301
        """Set the Client's D-Bus property"""
300
302
        client.Set(client_interface, self.property, self.value_to_set,
301
303
                   dbus_interface=dbus.PROPERTIES_IFACE)
314
316
    @value_to_set.setter
315
317
    def value_to_set(self, value):
316
318
        """When setting, convert value to a datetime.timedelta"""
317
 
        self._vts = string_to_delta(value).total_seconds() * 1000
 
319
        self._vts = int(round(value.total_seconds() * 1000))
318
320
 
319
321
# Actual (non-abstract) command classes
320
322
 
323
325
        self.verbose = verbose
324
326
 
325
327
    def output(self, clients):
 
328
        default_keywords = ("Name", "Enabled", "Timeout", "LastCheckedOK")
 
329
        keywords = default_keywords
326
330
        if self.verbose:
327
331
            keywords = self.all_keywords
328
 
        else:
329
 
            keywords = ("Name", "Enabled", "Timeout", "LastCheckedOK")
330
332
        return str(self.TableOfClients(clients.values(), keywords))
331
333
 
332
334
    class TableOfClients(object):
419
421
        return value
420
422
 
421
423
class IsEnabledCmd(Command):
422
 
    def run_on_one_client(self, client):
423
 
        if self.is_enabled(client):
 
424
    def run_on_one_client(self, client, properties):
 
425
        if self.is_enabled(client, properties):
424
426
            sys.exit(0)
425
427
        sys.exit(1)
426
 
    def is_enabled(self, client):
427
 
        return client.Get(client_interface, "Enabled",
428
 
                          dbus_interface=dbus.PROPERTIES_IFACE)
 
428
    def is_enabled(self, client, properties):
 
429
        return bool(properties["Enabled"])
429
430
 
430
431
class RemoveCmd(Command):
431
 
    def run_on_one_client(self, client):
 
432
    def run_on_one_client(self, client, properties):
432
433
        self.mandos.RemoveClient(client.__dbus_object_path__)
433
434
 
434
435
class ApproveCmd(Command):
435
 
    def run_on_one_client(self, client):
 
436
    def run_on_one_client(self, client, properties):
436
437
        client.Approve(dbus.Boolean(True),
437
438
                       dbus_interface=client_interface)
438
439
 
439
440
class DenyCmd(Command):
440
 
    def run_on_one_client(self, client):
 
441
    def run_on_one_client(self, client, properties):
441
442
        client.Approve(dbus.Boolean(False),
442
443
                       dbus_interface=client_interface)
443
444
 
476
477
    property = "Host"
477
478
 
478
479
class SetSecretCmd(PropertyCmd, ValueArgumentMixIn):
 
480
    @property
 
481
    def value_to_set(self):
 
482
        return self._vts
 
483
    @value_to_set.setter
 
484
    def value_to_set(self, value):
 
485
        """When setting, read data from supplied file object"""
 
486
        self._vts = value.read()
 
487
        value.close()
479
488
    property = "Secret"
480
489
 
481
490
class SetTimeoutCmd(PropertyCmd, MillisecondsValueArgumentMixIn):
496
505
                             MillisecondsValueArgumentMixIn):
497
506
    property = "ApprovalDuration"
498
507
 
499
 
def has_actions(options):
500
 
    return any((options.enable,
501
 
                options.disable,
502
 
                options.bump_timeout,
503
 
                options.start_checker,
504
 
                options.stop_checker,
505
 
                options.is_enabled,
506
 
                options.remove,
507
 
                options.checker is not None,
508
 
                options.timeout is not None,
509
 
                options.extended_timeout is not None,
510
 
                options.interval is not None,
511
 
                options.approved_by_default is not None,
512
 
                options.approval_delay is not None,
513
 
                options.approval_duration is not None,
514
 
                options.host is not None,
515
 
                options.secret is not None,
516
 
                options.approve,
517
 
                options.deny))
518
 
 
519
508
def add_command_line_options(parser):
520
509
    parser.add_argument("--version", action="version",
521
510
                        version="%(prog)s {}".format(version),
547
536
                        help="Remove client")
548
537
    parser.add_argument("-c", "--checker",
549
538
                        help="Set checker command for client")
550
 
    parser.add_argument("-t", "--timeout",
 
539
    parser.add_argument("-t", "--timeout", type=string_to_delta,
551
540
                        help="Set timeout for client")
552
 
    parser.add_argument("--extended-timeout",
 
541
    parser.add_argument("--extended-timeout", type=string_to_delta,
553
542
                        help="Set extended timeout for client")
554
 
    parser.add_argument("-i", "--interval",
 
543
    parser.add_argument("-i", "--interval", type=string_to_delta,
555
544
                        help="Set checker interval for client")
556
545
    approve_deny_default = parser.add_mutually_exclusive_group()
557
546
    approve_deny_default.add_argument(
562
551
        "--deny-by-default", action="store_false",
563
552
        dest="approved_by_default",
564
553
        help="Set client to be denied by default")
565
 
    parser.add_argument("--approval-delay",
 
554
    parser.add_argument("--approval-delay", type=string_to_delta,
566
555
                        help="Set delay before client approve/deny")
567
 
    parser.add_argument("--approval-duration",
 
556
    parser.add_argument("--approval-duration", type=string_to_delta,
568
557
                        help="Set duration of one client approval")
569
558
    parser.add_argument("-H", "--host", help="Set host for client")
570
559
    parser.add_argument("-s", "--secret",
581
570
    parser.add_argument("client", nargs="*", help="Client name")
582
571
 
583
572
 
584
 
def commands_and_clients_from_options(options):
 
573
def commands_from_options(options):
585
574
 
586
575
    commands = []
587
576
 
595
584
        commands.append(DisableCmd())
596
585
 
597
586
    if options.bump_timeout:
598
 
        commands.append(BumpTimeoutCmd(options.bump_timeout))
 
587
        commands.append(BumpTimeoutCmd())
599
588
 
600
589
    if options.start_checker:
601
590
        commands.append(StartCheckerCmd())
610
599
        commands.append(RemoveCmd())
611
600
 
612
601
    if options.checker is not None:
613
 
        commands.append(SetCheckerCmd())
 
602
        commands.append(SetCheckerCmd(options.checker))
614
603
 
615
604
    if options.timeout is not None:
616
605
        commands.append(SetTimeoutCmd(options.timeout))
620
609
            SetExtendedTimeoutCmd(options.extended_timeout))
621
610
 
622
611
    if options.interval is not None:
623
 
        command.append(SetIntervalCmd(options.interval))
 
612
        commands.append(SetIntervalCmd(options.interval))
624
613
 
625
614
    if options.approved_by_default is not None:
626
615
        if options.approved_by_default:
627
 
            command.append(ApproveByDefaultCmd())
 
616
            commands.append(ApproveByDefaultCmd())
628
617
        else:
629
 
            command.append(DenyByDefaultCmd())
 
618
            commands.append(DenyByDefaultCmd())
630
619
 
631
620
    if options.approval_delay is not None:
632
 
        command.append(SetApprovalDelayCmd(options.approval_delay))
 
621
        commands.append(SetApprovalDelayCmd(options.approval_delay))
633
622
 
634
623
    if options.approval_duration is not None:
635
 
        command.append(
 
624
        commands.append(
636
625
            SetApprovalDurationCmd(options.approval_duration))
637
626
 
638
627
    if options.host is not None:
639
 
        command.append(SetHostCmd(options.host))
 
628
        commands.append(SetHostCmd(options.host))
640
629
 
641
630
    if options.secret is not None:
642
 
        command.append(SetSecretCmd(options.secret))
 
631
        commands.append(SetSecretCmd(options.secret))
643
632
 
644
633
    if options.approve:
645
634
        commands.append(ApproveCmd())
652
641
    if not commands:
653
642
        commands.append(PrintTableCmd(verbose=options.verbose))
654
643
 
655
 
    return commands, options.client
656
 
 
657
 
 
658
 
def main():
659
 
    parser = argparse.ArgumentParser()
660
 
 
661
 
    add_command_line_options(parser)
662
 
 
663
 
    options = parser.parse_args()
 
644
    return commands
 
645
 
 
646
 
 
647
def check_option_syntax(parser, options):
 
648
 
 
649
    def has_actions(options):
 
650
        return any((options.enable,
 
651
                    options.disable,
 
652
                    options.bump_timeout,
 
653
                    options.start_checker,
 
654
                    options.stop_checker,
 
655
                    options.is_enabled,
 
656
                    options.remove,
 
657
                    options.checker is not None,
 
658
                    options.timeout is not None,
 
659
                    options.extended_timeout is not None,
 
660
                    options.interval is not None,
 
661
                    options.approved_by_default is not None,
 
662
                    options.approval_delay is not None,
 
663
                    options.approval_duration is not None,
 
664
                    options.host is not None,
 
665
                    options.secret is not None,
 
666
                    options.approve,
 
667
                    options.deny))
664
668
 
665
669
    if has_actions(options) and not (options.client or options.all):
666
670
        parser.error("Options require clients names or --all.")
674
678
    if options.is_enabled and len(options.client) > 1:
675
679
        parser.error("--is-enabled requires exactly one client")
676
680
 
677
 
    commands, clientnames = commands_and_clients_from_options(options)
 
681
 
 
682
def main():
 
683
    parser = argparse.ArgumentParser()
 
684
 
 
685
    add_command_line_options(parser)
 
686
 
 
687
    options = parser.parse_args()
 
688
 
 
689
    check_option_syntax(parser, options)
 
690
 
 
691
    clientnames = options.client
678
692
 
679
693
    try:
680
694
        bus = dbus.SystemBus()
727
741
                sys.exit(1)
728
742
 
729
743
    # Run all commands on clients
 
744
    commands = commands_from_options(options)
730
745
    for command in commands:
731
746
        command.run(mandos_serv, clients)
732
747
 
746
761
 
747
762
class Test_string_to_delta(unittest.TestCase):
748
763
    def test_handles_basic_rfc3339(self):
 
764
        self.assertEqual(string_to_delta("PT0S"),
 
765
                         datetime.timedelta())
 
766
        self.assertEqual(string_to_delta("P0D"),
 
767
                         datetime.timedelta())
 
768
        self.assertEqual(string_to_delta("PT1S"),
 
769
                         datetime.timedelta(0, 1))
749
770
        self.assertEqual(string_to_delta("PT2H"),
750
771
                         datetime.timedelta(0, 7200))
751
772
    def test_falls_back_to_pre_1_6_1_with_warning(self):
786
807
                testcase.assertEqual(dbus_interface,
787
808
                                     dbus.PROPERTIES_IFACE)
788
809
                self.attributes[property] = value
789
 
                self.calls.append(("Set", (interface, property, value,
790
 
                                           dbus_interface)))
791
810
            def Get(self, interface, property, dbus_interface):
792
811
                testcase.assertEqual(interface, client_interface)
793
812
                testcase.assertEqual(dbus_interface,
794
813
                                     dbus.PROPERTIES_IFACE)
795
 
                self.calls.append(("Get", (interface, property,
796
 
                                           dbus_interface)))
797
814
                return self.attributes[property]
798
815
            def Approve(self, approve, dbus_interface):
799
816
                testcase.assertEqual(dbus_interface, client_interface)
800
817
                self.calls.append(("Approve", (approve,
801
818
                                               dbus_interface)))
802
 
            def __getitem__(self, key):
803
 
                return self.attributes[key]
804
 
            def __setitem__(self, key, value):
805
 
                self.attributes[key] = value
806
 
        self.clients = collections.OrderedDict([
807
 
            ("foo",
808
 
             MockClient(
809
 
                 "foo",
810
 
                 KeyID=("92ed150794387c03ce684574b1139a65"
811
 
                        "94a34f895daaaf09fd8ea90a27cddb12"),
812
 
                 Secret=b"secret",
813
 
                 Host="foo.example.org",
814
 
                 Enabled=dbus.Boolean(True),
815
 
                 Timeout=300000,
816
 
                 LastCheckedOK="2019-02-03T00:00:00",
817
 
                 Created="2019-01-02T00:00:00",
818
 
                 Interval=120000,
819
 
                 Fingerprint=("778827225BA7DE539C5A"
820
 
                              "7CFA59CFF7CDBD9A5920"),
821
 
                 CheckerRunning=dbus.Boolean(False),
822
 
                 LastEnabled="2019-01-03T00:00:00",
823
 
                 ApprovalPending=dbus.Boolean(False),
824
 
                 ApprovedByDefault=dbus.Boolean(True),
825
 
                 LastApprovalRequest="",
826
 
                 ApprovalDelay=0,
827
 
                 ApprovalDuration=1000,
828
 
                 Checker="fping -q -- %(host)s",
829
 
                 ExtendedTimeout=900000,
830
 
                 Expires="2019-02-04T00:00:00",
831
 
                 LastCheckerStatus=0)),
832
 
            ("barbar",
833
 
             MockClient(
834
 
                 "barbar",
835
 
                 KeyID=("0558568eedd67d622f5c83b35a115f79"
836
 
                        "6ab612cff5ad227247e46c2b020f441c"),
837
 
                 Secret=b"secretbar",
838
 
                 Host="192.0.2.3",
839
 
                 Enabled=dbus.Boolean(True),
840
 
                 Timeout=300000,
841
 
                 LastCheckedOK="2019-02-04T00:00:00",
842
 
                 Created="2019-01-03T00:00:00",
843
 
                 Interval=120000,
844
 
                 Fingerprint=("3E393AEAEFB84C7E89E2"
845
 
                              "F547B3A107558FCA3A27"),
846
 
                 CheckerRunning=dbus.Boolean(True),
847
 
                 LastEnabled="2019-01-04T00:00:00",
848
 
                 ApprovalPending=dbus.Boolean(False),
849
 
                 ApprovedByDefault=dbus.Boolean(False),
850
 
                 LastApprovalRequest="2019-01-03T00:00:00",
851
 
                 ApprovalDelay=30000,
852
 
                 ApprovalDuration=1000,
853
 
                 Checker=":",
854
 
                 ExtendedTimeout=900000,
855
 
                 Expires="2019-02-05T00:00:00",
856
 
                 LastCheckerStatus=-2)),
 
819
        self.client = MockClient(
 
820
            "foo",
 
821
            KeyID=("92ed150794387c03ce684574b1139a65"
 
822
                   "94a34f895daaaf09fd8ea90a27cddb12"),
 
823
            Secret=b"secret",
 
824
            Host="foo.example.org",
 
825
            Enabled=dbus.Boolean(True),
 
826
            Timeout=300000,
 
827
            LastCheckedOK="2019-02-03T00:00:00",
 
828
            Created="2019-01-02T00:00:00",
 
829
            Interval=120000,
 
830
            Fingerprint=("778827225BA7DE539C5A"
 
831
                         "7CFA59CFF7CDBD9A5920"),
 
832
            CheckerRunning=dbus.Boolean(False),
 
833
            LastEnabled="2019-01-03T00:00:00",
 
834
            ApprovalPending=dbus.Boolean(False),
 
835
            ApprovedByDefault=dbus.Boolean(True),
 
836
            LastApprovalRequest="",
 
837
            ApprovalDelay=0,
 
838
            ApprovalDuration=1000,
 
839
            Checker="fping -q -- %(host)s",
 
840
            ExtendedTimeout=900000,
 
841
            Expires="2019-02-04T00:00:00",
 
842
            LastCheckerStatus=0)
 
843
        self.other_client = MockClient(
 
844
            "barbar",
 
845
            KeyID=("0558568eedd67d622f5c83b35a115f79"
 
846
                   "6ab612cff5ad227247e46c2b020f441c"),
 
847
            Secret=b"secretbar",
 
848
            Host="192.0.2.3",
 
849
            Enabled=dbus.Boolean(True),
 
850
            Timeout=300000,
 
851
            LastCheckedOK="2019-02-04T00:00:00",
 
852
            Created="2019-01-03T00:00:00",
 
853
            Interval=120000,
 
854
            Fingerprint=("3E393AEAEFB84C7E89E2"
 
855
                         "F547B3A107558FCA3A27"),
 
856
            CheckerRunning=dbus.Boolean(True),
 
857
            LastEnabled="2019-01-04T00:00:00",
 
858
            ApprovalPending=dbus.Boolean(False),
 
859
            ApprovedByDefault=dbus.Boolean(False),
 
860
            LastApprovalRequest="2019-01-03T00:00:00",
 
861
            ApprovalDelay=30000,
 
862
            ApprovalDuration=1000,
 
863
            Checker=":",
 
864
            ExtendedTimeout=900000,
 
865
            Expires="2019-02-05T00:00:00",
 
866
            LastCheckerStatus=-2)
 
867
        self.clients =  collections.OrderedDict(
 
868
            [
 
869
                (self.client, self.client.attributes),
 
870
                (self.other_client, self.other_client.attributes),
857
871
            ])
858
 
        self.client = self.clients["foo"]
 
872
        self.one_client = {self.client: self.client.attributes}
859
873
 
860
874
class TestPrintTableCmd(TestCmd):
861
875
    def test_normal(self):
875
889
"""[1:-1]
876
890
        self.assertEqual(output, expected_output)
877
891
    def test_one_client(self):
878
 
        output = PrintTableCmd().output({"foo": self.client})
 
892
        output = PrintTableCmd().output(self.one_client)
879
893
        expected_output = """
880
894
Name Enabled Timeout  Last Successful Check
881
895
foo  Yes     00:05:00 2019-02-03T00:00:00  
939
953
        json_data = json.loads(DumpJSONCmd().output(self.clients))
940
954
        self.assertDictEqual(json_data, self.expected_json)
941
955
    def test_one_client(self):
942
 
        clients = {"foo": self.client}
 
956
        clients = self.one_client
943
957
        json_data = json.loads(DumpJSONCmd().output(clients))
944
958
        expected_json = {"foo": self.expected_json["foo"]}
945
959
        self.assertDictEqual(json_data, expected_json)
946
960
 
947
961
class TestIsEnabledCmd(TestCmd):
948
962
    def test_is_enabled(self):
949
 
        self.assertTrue(all(IsEnabledCmd().is_enabled(client)
950
 
                            for client in self.clients.values()))
951
 
    def test_is_enabled_does_get_attribute(self):
952
 
        self.assertTrue(IsEnabledCmd().is_enabled(self.client))
953
 
        self.assertListEqual(self.client.calls,
954
 
                             [("Get",
955
 
                               ("se.recompile.Mandos.Client",
956
 
                                "Enabled",
957
 
                                "org.freedesktop.DBus.Properties"))])
 
963
        self.assertTrue(all(IsEnabledCmd().is_enabled(client, properties)
 
964
                            for client, properties in self.clients.items()))
958
965
    def test_is_enabled_run_exits_successfully(self):
959
966
        with self.assertRaises(SystemExit) as e:
960
 
            IsEnabledCmd().run(None, [self.client])
 
967
            IsEnabledCmd().run(None, self.one_client)
961
968
        if e.exception.code is not None:
962
969
            self.assertEqual(e.exception.code, 0)
963
970
        else:
964
971
            self.assertIsNone(e.exception.code)
965
972
    def test_is_enabled_run_exits_with_failure(self):
966
 
        self.client["Enabled"] = dbus.Boolean(False)
 
973
        self.client.attributes["Enabled"] = dbus.Boolean(False)
967
974
        with self.assertRaises(SystemExit) as e:
968
 
            IsEnabledCmd().run(None, [self.client])
 
975
            IsEnabledCmd().run(None, self.one_client)
969
976
        if isinstance(e.exception.code, int):
970
977
            self.assertNotEqual(e.exception.code, 0)
971
978
        else:
979
986
            def RemoveClient(self, dbus_path):
980
987
                self.calls.append(("RemoveClient", (dbus_path,)))
981
988
        mandos = MockMandos()
982
 
        RemoveCmd().run(mandos, [self.client])
983
 
        self.assertEqual(len(mandos.calls), 1)
984
 
        self.assertListEqual(mandos.calls,
985
 
                             [("RemoveClient",
986
 
                               (self.client.__dbus_object_path__,))])
 
989
        super(TestRemoveCmd, self).setUp()
 
990
        RemoveCmd().run(mandos, self.clients)
 
991
        self.assertEqual(len(mandos.calls), 2)
 
992
        for client in self.clients:
 
993
            self.assertIn(("RemoveClient",
 
994
                           (client.__dbus_object_path__,)),
 
995
                          mandos.calls)
987
996
 
988
997
class TestApproveCmd(TestCmd):
989
998
    def test_approve(self):
990
 
        ApproveCmd().run(None, [self.client])
991
 
        self.assertListEqual(self.client.calls,
992
 
                             [("Approve", (True, client_interface))])
 
999
        ApproveCmd().run(None, self.clients)
 
1000
        for client in self.clients:
 
1001
            self.assertIn(("Approve", (True, client_interface)),
 
1002
                          client.calls)
 
1003
 
993
1004
class TestDenyCmd(TestCmd):
 
1005
    def test_deny(self):
 
1006
        DenyCmd().run(None, self.clients)
 
1007
        for client in self.clients:
 
1008
            self.assertIn(("Approve", (False, client_interface)),
 
1009
                          client.calls)
 
1010
 
 
1011
class TestEnableCmd(TestCmd):
 
1012
    def test_enable(self):
 
1013
        for client in self.clients:
 
1014
            client.attributes["Enabled"] = False
 
1015
 
 
1016
        EnableCmd().run(None, self.clients)
 
1017
 
 
1018
        for client in self.clients:
 
1019
            self.assertTrue(client.attributes["Enabled"])
 
1020
 
 
1021
class TestDisableCmd(TestCmd):
 
1022
    def test_disable(self):
 
1023
        DisableCmd().run(None, self.clients)
 
1024
 
 
1025
        for client in self.clients:
 
1026
            self.assertFalse(client.attributes["Enabled"])
 
1027
 
 
1028
class Unique(object):
 
1029
    """Class for objects which exist only to be unique objects, since
 
1030
unittest.mock.sentinel only exists in Python 3.3"""
 
1031
 
 
1032
class TestPropertyCmd(TestCmd):
 
1033
    """Abstract class for tests of PropertyCmd classes"""
 
1034
    def runTest(self):
 
1035
        if not hasattr(self, "command"):
 
1036
            return
 
1037
        values_to_get = getattr(self, "values_to_get",
 
1038
                                self.values_to_set)
 
1039
        for value_to_set, value_to_get in zip(self.values_to_set,
 
1040
                                              values_to_get):
 
1041
            for client in self.clients:
 
1042
                old_value = client.attributes[self.property]
 
1043
                self.assertNotIsInstance(old_value, Unique)
 
1044
                client.attributes[self.property] = Unique()
 
1045
            self.run_command(value_to_set, self.clients)
 
1046
            for client in self.clients:
 
1047
                value = client.attributes[self.property]
 
1048
                self.assertNotIsInstance(value, Unique)
 
1049
                self.assertEqual(value, value_to_get)
 
1050
    def run_command(self, value, clients):
 
1051
        self.command().run(None, clients)
 
1052
 
 
1053
class TestBumpTimeoutCmd(TestPropertyCmd):
 
1054
    command = BumpTimeoutCmd
 
1055
    property = "LastCheckedOK"
 
1056
    values_to_set = [""]
 
1057
 
 
1058
class TestStartCheckerCmd(TestPropertyCmd):
 
1059
    command = StartCheckerCmd
 
1060
    property = "CheckerRunning"
 
1061
    values_to_set = [dbus.Boolean(True)]
 
1062
 
 
1063
class TestStopCheckerCmd(TestPropertyCmd):
 
1064
    command = StopCheckerCmd
 
1065
    property = "CheckerRunning"
 
1066
    values_to_set = [dbus.Boolean(False)]
 
1067
 
 
1068
class TestApproveByDefaultCmd(TestPropertyCmd):
 
1069
    command = ApproveByDefaultCmd
 
1070
    property = "ApprovedByDefault"
 
1071
    values_to_set = [dbus.Boolean(True)]
 
1072
 
 
1073
class TestDenyByDefaultCmd(TestPropertyCmd):
 
1074
    command = DenyByDefaultCmd
 
1075
    property = "ApprovedByDefault"
 
1076
    values_to_set = [dbus.Boolean(False)]
 
1077
 
 
1078
class TestValueArgumentPropertyCmd(TestPropertyCmd):
 
1079
    """Abstract class for tests of PropertyCmd classes using the
 
1080
ValueArgumentMixIn"""
 
1081
    def runTest(self):
 
1082
        if type(self) is TestValueArgumentPropertyCmd:
 
1083
            return
 
1084
        return super(TestValueArgumentPropertyCmd, self).runTest()
 
1085
    def run_command(self, value, clients):
 
1086
        self.command(value).run(None, clients)
 
1087
 
 
1088
class TestSetCheckerCmd(TestValueArgumentPropertyCmd):
 
1089
    command = SetCheckerCmd
 
1090
    property = "Checker"
 
1091
    values_to_set = ["", ":", "fping -q -- %s"]
 
1092
 
 
1093
class TestSetHostCmd(TestValueArgumentPropertyCmd):
 
1094
    command = SetHostCmd
 
1095
    property = "Host"
 
1096
    values_to_set = ["192.0.2.3", "foo.example.org"]
 
1097
 
 
1098
class TestSetSecretCmd(TestValueArgumentPropertyCmd):
 
1099
    command = SetSecretCmd
 
1100
    property = "Secret"
 
1101
    values_to_set = [open("/dev/null", "rb"),
 
1102
                     io.BytesIO(b"secret\0xyzzy\nbar")]
 
1103
    values_to_get = [b"", b"secret\0xyzzy\nbar"]
 
1104
 
 
1105
class TestSetTimeoutCmd(TestValueArgumentPropertyCmd):
 
1106
    command = SetTimeoutCmd
 
1107
    property = "Timeout"
 
1108
    values_to_set = [datetime.timedelta(),
 
1109
                     datetime.timedelta(minutes=5),
 
1110
                     datetime.timedelta(seconds=1),
 
1111
                     datetime.timedelta(weeks=1),
 
1112
                     datetime.timedelta(weeks=52)]
 
1113
    values_to_get = [0, 300000, 1000, 604800000, 31449600000]
 
1114
 
 
1115
class TestSetExtendedTimeoutCmd(TestValueArgumentPropertyCmd):
 
1116
    command = SetExtendedTimeoutCmd
 
1117
    property = "ExtendedTimeout"
 
1118
    values_to_set = [datetime.timedelta(),
 
1119
                     datetime.timedelta(minutes=5),
 
1120
                     datetime.timedelta(seconds=1),
 
1121
                     datetime.timedelta(weeks=1),
 
1122
                     datetime.timedelta(weeks=52)]
 
1123
    values_to_get = [0, 300000, 1000, 604800000, 31449600000]
 
1124
 
 
1125
class TestSetIntervalCmd(TestValueArgumentPropertyCmd):
 
1126
    command = SetIntervalCmd
 
1127
    property = "Interval"
 
1128
    values_to_set = [datetime.timedelta(),
 
1129
                     datetime.timedelta(minutes=5),
 
1130
                     datetime.timedelta(seconds=1),
 
1131
                     datetime.timedelta(weeks=1),
 
1132
                     datetime.timedelta(weeks=52)]
 
1133
    values_to_get = [0, 300000, 1000, 604800000, 31449600000]
 
1134
 
 
1135
class TestSetApprovalDelayCmd(TestValueArgumentPropertyCmd):
 
1136
    command = SetApprovalDelayCmd
 
1137
    property = "ApprovalDelay"
 
1138
    values_to_set = [datetime.timedelta(),
 
1139
                     datetime.timedelta(minutes=5),
 
1140
                     datetime.timedelta(seconds=1),
 
1141
                     datetime.timedelta(weeks=1),
 
1142
                     datetime.timedelta(weeks=52)]
 
1143
    values_to_get = [0, 300000, 1000, 604800000, 31449600000]
 
1144
 
 
1145
class TestSetApprovalDurationCmd(TestValueArgumentPropertyCmd):
 
1146
    command = SetApprovalDurationCmd
 
1147
    property = "ApprovalDuration"
 
1148
    values_to_set = [datetime.timedelta(),
 
1149
                     datetime.timedelta(minutes=5),
 
1150
                     datetime.timedelta(seconds=1),
 
1151
                     datetime.timedelta(weeks=1),
 
1152
                     datetime.timedelta(weeks=52)]
 
1153
    values_to_get = [0, 300000, 1000, 604800000, 31449600000]
 
1154
 
 
1155
class Test_command_from_options(unittest.TestCase):
 
1156
    def setUp(self):
 
1157
        self.parser = argparse.ArgumentParser()
 
1158
        add_command_line_options(self.parser)
 
1159
    def assert_command_from_args(self, args, command_cls, **cmd_attrs):
 
1160
        """Assert that parsing ARGS should result in an instance of
 
1161
COMMAND_CLS with (optionally) all supplied attributes (CMD_ATTRS)."""
 
1162
        options = self.parser.parse_args(args)
 
1163
        check_option_syntax(self.parser, options)
 
1164
        commands = commands_from_options(options)
 
1165
        self.assertEqual(len(commands), 1)
 
1166
        command = commands[0]
 
1167
        self.assertIsInstance(command, command_cls)
 
1168
        for key, value in cmd_attrs.items():
 
1169
            self.assertEqual(getattr(command, key), value)
 
1170
    def test_print_table(self):
 
1171
        self.assert_command_from_args([], PrintTableCmd,
 
1172
                                      verbose=False)
 
1173
 
 
1174
    def test_print_table_verbose(self):
 
1175
        self.assert_command_from_args(["--verbose"], PrintTableCmd,
 
1176
                                      verbose=True)
 
1177
 
 
1178
    def test_print_table_verbose_short(self):
 
1179
        self.assert_command_from_args(["-v"], PrintTableCmd,
 
1180
                                      verbose=True)
 
1181
 
 
1182
    def test_enable(self):
 
1183
        self.assert_command_from_args(["--enable", "foo"], EnableCmd)
 
1184
 
 
1185
    def test_enable_short(self):
 
1186
        self.assert_command_from_args(["-e", "foo"], EnableCmd)
 
1187
 
 
1188
    def test_disable(self):
 
1189
        self.assert_command_from_args(["--disable", "foo"],
 
1190
                                      DisableCmd)
 
1191
 
 
1192
    def test_disable_short(self):
 
1193
        self.assert_command_from_args(["-d", "foo"], DisableCmd)
 
1194
 
 
1195
    def test_bump_timeout(self):
 
1196
        self.assert_command_from_args(["--bump-timeout", "foo"],
 
1197
                                      BumpTimeoutCmd)
 
1198
 
 
1199
    def test_bump_timeout_short(self):
 
1200
        self.assert_command_from_args(["-b", "foo"], BumpTimeoutCmd)
 
1201
 
 
1202
    def test_start_checker(self):
 
1203
        self.assert_command_from_args(["--start-checker", "foo"],
 
1204
                                      StartCheckerCmd)
 
1205
 
 
1206
    def test_stop_checker(self):
 
1207
        self.assert_command_from_args(["--stop-checker", "foo"],
 
1208
                                      StopCheckerCmd)
 
1209
 
 
1210
    def test_remove(self):
 
1211
        self.assert_command_from_args(["--remove", "foo"],
 
1212
                                      RemoveCmd)
 
1213
 
 
1214
    def test_remove_short(self):
 
1215
        self.assert_command_from_args(["-r", "foo"], RemoveCmd)
 
1216
 
 
1217
    def test_checker(self):
 
1218
        self.assert_command_from_args(["--checker", ":", "foo"],
 
1219
                                      SetCheckerCmd, value_to_set=":")
 
1220
 
 
1221
    def test_checker_empty(self):
 
1222
        self.assert_command_from_args(["--checker", "", "foo"],
 
1223
                                      SetCheckerCmd, value_to_set="")
 
1224
 
 
1225
    def test_checker_short(self):
 
1226
        self.assert_command_from_args(["-c", ":", "foo"],
 
1227
                                      SetCheckerCmd, value_to_set=":")
 
1228
 
 
1229
    def test_timeout(self):
 
1230
        self.assert_command_from_args(["--timeout", "PT5M", "foo"],
 
1231
                                      SetTimeoutCmd,
 
1232
                                      value_to_set=300000)
 
1233
 
 
1234
    def test_timeout_short(self):
 
1235
        self.assert_command_from_args(["-t", "PT5M", "foo"],
 
1236
                                      SetTimeoutCmd,
 
1237
                                      value_to_set=300000)
 
1238
 
 
1239
    def test_extended_timeout(self):
 
1240
        self.assert_command_from_args(["--extended-timeout", "PT15M",
 
1241
                                       "foo"],
 
1242
                                      SetExtendedTimeoutCmd,
 
1243
                                      value_to_set=900000)
 
1244
 
 
1245
    def test_interval(self):
 
1246
        self.assert_command_from_args(["--interval", "PT2M", "foo"],
 
1247
                                      SetIntervalCmd,
 
1248
                                      value_to_set=120000)
 
1249
 
 
1250
    def test_interval_short(self):
 
1251
        self.assert_command_from_args(["-i", "PT2M", "foo"],
 
1252
                                      SetIntervalCmd,
 
1253
                                      value_to_set=120000)
 
1254
 
 
1255
    def test_approve_by_default(self):
 
1256
        self.assert_command_from_args(["--approve-by-default", "foo"],
 
1257
                                      ApproveByDefaultCmd)
 
1258
 
 
1259
    def test_deny_by_default(self):
 
1260
        self.assert_command_from_args(["--deny-by-default", "foo"],
 
1261
                                      DenyByDefaultCmd)
 
1262
 
 
1263
    def test_approval_delay(self):
 
1264
        self.assert_command_from_args(["--approval-delay", "PT30S",
 
1265
                                       "foo"], SetApprovalDelayCmd,
 
1266
                                      value_to_set=30000)
 
1267
 
 
1268
    def test_approval_duration(self):
 
1269
        self.assert_command_from_args(["--approval-duration", "PT1S",
 
1270
                                       "foo"], SetApprovalDurationCmd,
 
1271
                                      value_to_set=1000)
 
1272
 
 
1273
    def test_host(self):
 
1274
        self.assert_command_from_args(["--host", "foo.example.org",
 
1275
                                       "foo"], SetHostCmd,
 
1276
                                      value_to_set="foo.example.org")
 
1277
 
 
1278
    def test_host_short(self):
 
1279
        self.assert_command_from_args(["-H", "foo.example.org",
 
1280
                                       "foo"], SetHostCmd,
 
1281
                                      value_to_set="foo.example.org")
 
1282
 
 
1283
    def test_secret_devnull(self):
 
1284
        self.assert_command_from_args(["--secret", os.path.devnull,
 
1285
                                       "foo"], SetSecretCmd,
 
1286
                                      value_to_set=b"")
 
1287
 
 
1288
    def test_secret_tempfile(self):
 
1289
        with tempfile.NamedTemporaryFile(mode="r+b") as f:
 
1290
            value = b"secret\0xyzzy\nbar"
 
1291
            f.write(value)
 
1292
            f.seek(0)
 
1293
            self.assert_command_from_args(["--secret", f.name,
 
1294
                                           "foo"], SetSecretCmd,
 
1295
                                          value_to_set=value)
 
1296
 
 
1297
    def test_secret_devnull_short(self):
 
1298
        self.assert_command_from_args(["-s", os.path.devnull, "foo"],
 
1299
                                      SetSecretCmd, value_to_set=b"")
 
1300
 
 
1301
    def test_secret_tempfile_short(self):
 
1302
        with tempfile.NamedTemporaryFile(mode="r+b") as f:
 
1303
            value = b"secret\0xyzzy\nbar"
 
1304
            f.write(value)
 
1305
            f.seek(0)
 
1306
            self.assert_command_from_args(["-s", f.name, "foo"],
 
1307
                                          SetSecretCmd,
 
1308
                                          value_to_set=value)
 
1309
 
994
1310
    def test_approve(self):
995
 
        DenyCmd().run(None, [self.client])
996
 
        self.assertListEqual(self.client.calls,
997
 
                             [("Approve", (False, client_interface))])
 
1311
        self.assert_command_from_args(["--approve", "foo"],
 
1312
                                      ApproveCmd)
 
1313
 
 
1314
    def test_approve_short(self):
 
1315
        self.assert_command_from_args(["-A", "foo"], ApproveCmd)
 
1316
 
 
1317
    def test_deny(self):
 
1318
        self.assert_command_from_args(["--deny", "foo"], DenyCmd)
 
1319
 
 
1320
    def test_deny_short(self):
 
1321
        self.assert_command_from_args(["-D", "foo"], DenyCmd)
 
1322
 
 
1323
    def test_dump_json(self):
 
1324
        self.assert_command_from_args(["--dump-json"], DumpJSONCmd)
 
1325
 
 
1326
    def test_is_enabled(self):
 
1327
        self.assert_command_from_args(["--is-enabled", "foo"],
 
1328
                                      IsEnabledCmd)
 
1329
 
 
1330
    def test_is_enabled_short(self):
 
1331
        self.assert_command_from_args(["-V", "foo"], IsEnabledCmd)
998
1332
 
999
1333
 
1000
1334