salt/tests/integration/modules/test_linux_shadow.py

Ignoring revisions in .git-blame-ignore-revs. Click here to bypass and see the normal blame view.

254 lines
8.6 KiB
Python
Raw Normal View History

2020-04-02 20:10:20 -05:00
"""
integration tests for shadow linux
2020-04-02 20:10:20 -05:00
"""
import os
import pytest
from saltfactories.utils import random_string
import salt.modules.linux_shadow
import salt.utils.files
Use explicit unicode strings + break up salt.utils This PR is part of what will be an ongoing effort to use explicit unicode strings in Salt. Because Python 3 does not suport Python 2's raw unicode string syntax (i.e. `ur'\d+'`), we must use `salt.utils.locales.sdecode()` to ensure that the raw string is unicode. However, because of how `salt/utils/__init__.py` has evolved into the hulking monstrosity it is today, this means importing a large module in places where it is not needed, which could negatively impact performance. For this reason, this PR also breaks out some of the functions from `salt/utils/__init__.py` into new/existing modules under `salt/utils/`. The long term goal will be that the modules within this directory do not depend on importing `salt.utils`. A summary of the changes in this PR is as follows: * Moves the following functions from `salt.utils` to new locations (including a deprecation warning if invoked from `salt.utils`): `to_bytes`, `to_str`, `to_unicode`, `str_to_num`, `is_quoted`, `dequote`, `is_hex`, `is_bin_str`, `rand_string`, `contains_whitespace`, `clean_kwargs`, `invalid_kwargs`, `which`, `which_bin`, `path_join`, `shlex_split`, `rand_str`, `is_windows`, `is_proxy`, `is_linux`, `is_darwin`, `is_sunos`, `is_smartos`, `is_smartos_globalzone`, `is_smartos_zone`, `is_freebsd`, `is_netbsd`, `is_openbsd`, `is_aix` * Moves the functions already deprecated by @rallytime to the bottom of `salt/utils/__init__.py` for better organization, so we can keep the deprecated ones separate from the ones yet to be deprecated as we continue to break up `salt.utils` * Updates `salt/*.py` and all files under `salt/client/` to use explicit unicode string literals. * Gets rid of implicit imports of `salt.utils` (e.g. `from salt.utils import foo` becomes `import salt.utils.foo as foo`). * Renames the `test.rand_str` function to `test.random_hash` to more accurately reflect what it does * Modifies `salt.utils.stringutils.random()` (née `salt.utils.rand_string()`) such that it returns a string matching the passed size. Previously this function would get `size` bytes from `os.urandom()`, base64-encode it, and return the result, which would in most cases not be equal to the passed size.
2017-07-24 20:47:15 -05:00
import salt.utils.platform
from tests.support.case import ModuleCase
2020-04-02 20:10:20 -05:00
@pytest.mark.skip_if_not_root
@pytest.mark.skip_unless_on_linux
@pytest.mark.slow_test
class ShadowModuleTest(ModuleCase):
2020-04-02 20:10:20 -05:00
"""
Validate the linux shadow system module
2020-04-02 20:10:20 -05:00
"""
def setUp(self):
2020-04-02 20:10:20 -05:00
"""
Get current settings
2020-04-02 20:10:20 -05:00
"""
self._password = self.run_function("shadow.gen_password", ["Password1234"])
if "ERROR" in self._password:
self.fail(f"Failed to generate password: {self._password}")
super().setUp()
self._no_user = random_string("tu-", uppercase=False)
self._test_user = random_string("tu-", uppercase=False)
self._password = salt.modules.linux_shadow.gen_password("Password1234")
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_info(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.info
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
ret = self.run_function("shadow.info", [self._test_user])
self.assertEqual(ret["name"], self._test_user)
# User does not exist
ret = self.run_function("shadow.info", [self._no_user])
self.assertEqual(ret["name"], "")
@pytest.mark.destructive_test
@pytest.mark.slow_test
2025-01-08 15:40:50 -07:00
@pytest.mark.skip_if_binaries_missing("passwd")
def test_del_password(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.del_password
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(self.run_function("shadow.del_password", [self._test_user]))
2025-01-08 15:40:50 -07:00
self.assertIn(
self.run_function("shadow.info", [self._test_user])["passwd"],
["", "!", "!!"],
)
# User does not exist
self.assertFalse(self.run_function("shadow.del_password", [self._no_user]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_password(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_password
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(
self.run_function("shadow.set_password", [self._test_user, self._password])
2020-04-02 20:10:20 -05:00
)
# User does not exist
self.assertFalse(
self.run_function("shadow.set_password", [self._no_user, self._password])
2020-04-02 20:10:20 -05:00
)
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_inactdays(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_inactdays
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(
self.run_function("shadow.set_inactdays", [self._test_user, 12])
2020-04-02 20:10:20 -05:00
)
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.set_inactdays", [self._no_user, 12]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_maxdays(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_maxdays
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(self.run_function("shadow.set_maxdays", [self._test_user, 12]))
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.set_maxdays", [self._no_user, 12]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_mindays(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_mindays
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(self.run_function("shadow.set_mindays", [self._test_user, 12]))
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.set_mindays", [self._no_user, 12]))
@pytest.mark.flaky(max_runs=4)
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_lock_password(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.lock_password
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
self.run_function("shadow.set_password", [self._test_user, self._password])
# Correct Functionality
self.assertTrue(self.run_function("shadow.lock_password", [self._test_user]))
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.lock_password", [self._no_user]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_unlock_password(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.lock_password
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
self.run_function("shadow.set_password", [self._test_user, self._password])
# Correct Functionality
self.assertTrue(self.run_function("shadow.unlock_password", [self._test_user]))
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.unlock_password", [self._no_user]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_warndays(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_warndays
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(self.run_function("shadow.set_warndays", [self._test_user, 12]))
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(self.run_function("shadow.set_warndays", [self._no_user, 12]))
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_date(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_date
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(
self.run_function("shadow.set_date", [self._test_user, "2016-08-19"])
2020-04-02 20:10:20 -05:00
)
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(
self.run_function("shadow.set_date", [self._no_user, "2016-08-19"])
2020-04-02 20:10:20 -05:00
)
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_expire(self):
2020-04-02 20:10:20 -05:00
"""
Test shadow.set_exipre
2020-04-02 20:10:20 -05:00
"""
2019-03-17 18:30:02 +00:00
self.addCleanup(self.run_function, "user.delete", [self._test_user])
self.run_function("user.add", [self._test_user])
# Correct Functionality
self.assertTrue(
self.run_function("shadow.set_expire", [self._test_user, "2016-08-25"])
2020-04-02 20:10:20 -05:00
)
# User does not exist (set_inactdays return None is user does not exist)
self.assertFalse(
self.run_function("shadow.set_expire", [self._no_user, "2016-08-25"])
2020-04-02 20:10:20 -05:00
)
@pytest.mark.destructive_test
@pytest.mark.slow_test
def test_set_del_root_password(self):
2020-04-02 20:10:20 -05:00
"""
Test set/del password for root
2020-04-02 20:10:20 -05:00
"""
# saving shadow file
if not os.access("/etc/shadow", os.R_OK | os.W_OK):
self.skipTest("Could not save initial state of /etc/shadow")
2019-03-17 18:30:02 +00:00
def restore_shadow_file(contents):
# restore shadow file
with salt.utils.files.fopen("/etc/shadow", "w") as wfh:
2019-03-17 18:30:02 +00:00
wfh.write(contents)
with salt.utils.files.fopen("/etc/shadow", "r") as rfh:
2019-03-17 18:30:02 +00:00
contents = rfh.read()
self.addCleanup(restore_shadow_file, contents)
# set root password
self.assertTrue(
self.run_function("shadow.set_password", ["root", self._password])
2019-03-17 18:30:02 +00:00
)
self.assertEqual(
self.run_function("shadow.info", ["root"])["passwd"], self._password
2020-04-02 20:10:20 -05:00
)
# delete root password
self.assertTrue(self.run_function("shadow.del_password", ["root"]))
2019-03-17 18:30:02 +00:00
self.assertEqual(self.run_function("shadow.info", ["root"])["passwd"], "")