2017-02-26 20:05:36 +00:00
|
|
|
# -*- coding: utf-8 -*-
|
|
|
|
'''
|
|
|
|
Unit tests for the Vault runner
|
|
|
|
'''
|
|
|
|
|
|
|
|
# Import Python Libs
|
|
|
|
from __future__ import absolute_import
|
|
|
|
import logging
|
|
|
|
|
|
|
|
# Import Salt Testing Libs
|
2017-03-21 23:56:24 +00:00
|
|
|
from tests.support.mixins import LoaderModuleMockMixin
|
2017-02-27 15:59:04 +00:00
|
|
|
from tests.support.unit import skipIf, TestCase
|
|
|
|
from tests.support.mock import (
|
2017-02-26 20:05:36 +00:00
|
|
|
MagicMock,
|
|
|
|
patch,
|
|
|
|
NO_MOCK,
|
|
|
|
NO_MOCK_REASON
|
|
|
|
)
|
|
|
|
|
2017-02-27 15:59:04 +00:00
|
|
|
# Import salt libs
|
Use explicit unicode strings + break up salt.utils
This PR is part of what will be an ongoing effort to use explicit
unicode strings in Salt. Because Python 3 does not suport Python 2's raw
unicode string syntax (i.e. `ur'\d+'`), we must use
`salt.utils.locales.sdecode()` to ensure that the raw string is unicode.
However, because of how `salt/utils/__init__.py` has evolved into the
hulking monstrosity it is today, this means importing a large module in
places where it is not needed, which could negatively impact
performance. For this reason, this PR also breaks out some of the
functions from `salt/utils/__init__.py` into new/existing modules under
`salt/utils/`. The long term goal will be that the modules within this
directory do not depend on importing `salt.utils`.
A summary of the changes in this PR is as follows:
* Moves the following functions from `salt.utils` to new locations
(including a deprecation warning if invoked from `salt.utils`):
`to_bytes`, `to_str`, `to_unicode`, `str_to_num`, `is_quoted`,
`dequote`, `is_hex`, `is_bin_str`, `rand_string`,
`contains_whitespace`, `clean_kwargs`, `invalid_kwargs`, `which`,
`which_bin`, `path_join`, `shlex_split`, `rand_str`, `is_windows`,
`is_proxy`, `is_linux`, `is_darwin`, `is_sunos`, `is_smartos`,
`is_smartos_globalzone`, `is_smartos_zone`, `is_freebsd`, `is_netbsd`,
`is_openbsd`, `is_aix`
* Moves the functions already deprecated by @rallytime to the bottom of
`salt/utils/__init__.py` for better organization, so we can keep the
deprecated ones separate from the ones yet to be deprecated as we
continue to break up `salt.utils`
* Updates `salt/*.py` and all files under `salt/client/` to use explicit
unicode string literals.
* Gets rid of implicit imports of `salt.utils` (e.g. `from salt.utils
import foo` becomes `import salt.utils.foo as foo`).
* Renames the `test.rand_str` function to `test.random_hash` to more
accurately reflect what it does
* Modifies `salt.utils.stringutils.random()` (née `salt.utils.rand_string()`)
such that it returns a string matching the passed size. Previously
this function would get `size` bytes from `os.urandom()`,
base64-encode it, and return the result, which would in most cases not
be equal to the passed size.
2017-07-25 01:47:15 +00:00
|
|
|
from salt.ext import six
|
2017-03-21 17:15:36 +00:00
|
|
|
import salt.runners.vault as vault
|
2017-02-26 20:05:36 +00:00
|
|
|
|
|
|
|
log = logging.getLogger(__name__)
|
|
|
|
|
|
|
|
|
2017-03-21 23:56:24 +00:00
|
|
|
class VaultTest(TestCase, LoaderModuleMockMixin):
|
2017-02-26 20:05:36 +00:00
|
|
|
'''
|
|
|
|
Tests for the runner module of the Vault integration
|
|
|
|
'''
|
|
|
|
|
2017-03-22 12:12:36 +00:00
|
|
|
def setup_loader_modules(self):
|
|
|
|
return {vault: {}}
|
2017-03-21 23:56:24 +00:00
|
|
|
|
2017-02-26 20:05:36 +00:00
|
|
|
def setUp(self):
|
|
|
|
self.grains = {
|
|
|
|
'id': 'test-minion',
|
|
|
|
'roles': ['web', 'database'],
|
|
|
|
'aux': ['foo', 'bar'],
|
|
|
|
'deep': {
|
|
|
|
'foo': {
|
|
|
|
'bar': {
|
|
|
|
'baz': [
|
|
|
|
'hello',
|
|
|
|
'world'
|
|
|
|
]
|
|
|
|
}
|
|
|
|
}
|
|
|
|
},
|
2017-04-04 14:50:35 +00:00
|
|
|
'mixedcase': 'UP-low-UP'
|
2017-02-26 20:05:36 +00:00
|
|
|
}
|
|
|
|
|
2017-03-21 23:56:24 +00:00
|
|
|
def tearDown(self):
|
|
|
|
del self.grains
|
|
|
|
|
2017-02-26 20:05:36 +00:00
|
|
|
def test_pattern_list_expander(self):
|
|
|
|
'''
|
|
|
|
Ensure _expand_pattern_lists works as intended:
|
|
|
|
- Expand list-valued patterns
|
|
|
|
- Do not change non-list-valued tokens
|
|
|
|
'''
|
|
|
|
cases = {
|
|
|
|
'no-tokens-to-replace': ['no-tokens-to-replace'],
|
|
|
|
'single-dict:{minion}': ['single-dict:{minion}'],
|
|
|
|
'single-list:{grains[roles]}': ['single-list:web', 'single-list:database'],
|
|
|
|
'multiple-lists:{grains[roles]}+{grains[aux]}': [
|
|
|
|
'multiple-lists:web+foo',
|
|
|
|
'multiple-lists:web+bar',
|
|
|
|
'multiple-lists:database+foo',
|
|
|
|
'multiple-lists:database+bar',
|
|
|
|
],
|
|
|
|
'single-list-with-dicts:{grains[id]}+{grains[roles]}+{grains[id]}': [
|
|
|
|
'single-list-with-dicts:{grains[id]}+web+{grains[id]}',
|
|
|
|
'single-list-with-dicts:{grains[id]}+database+{grains[id]}'
|
|
|
|
],
|
|
|
|
'deeply-nested-list:{grains[deep][foo][bar][baz]}': [
|
|
|
|
'deeply-nested-list:hello',
|
|
|
|
'deeply-nested-list:world'
|
|
|
|
]
|
|
|
|
}
|
|
|
|
|
|
|
|
# The mappings dict is assembled in _get_policies, so emulate here
|
|
|
|
mappings = {'minion': self.grains['id'], 'grains': self.grains}
|
|
|
|
for case, correct_output in six.iteritems(cases):
|
|
|
|
output = vault._expand_pattern_lists(case, **mappings) # pylint: disable=protected-access
|
|
|
|
diff = set(output).symmetric_difference(set(correct_output))
|
|
|
|
if len(diff) != 0:
|
|
|
|
log.debug('Test {0} failed'.format(case))
|
|
|
|
log.debug('Expected:\n\t{0}\nGot\n\t{1}'.format(output, correct_output))
|
|
|
|
log.debug('Difference:\n\t{0}'.format(diff))
|
|
|
|
self.assertEqual(output, correct_output)
|
|
|
|
|
2017-04-04 14:50:35 +00:00
|
|
|
def test_get_policies_for_nonexisting_minions(self):
|
|
|
|
minion_id = 'salt_master'
|
|
|
|
# For non-existing minions, or the master-minion, grains will be None
|
|
|
|
cases = {
|
|
|
|
'no-tokens-to-replace': ['no-tokens-to-replace'],
|
|
|
|
'single-dict:{minion}': ['single-dict:{0}'.format(minion_id)],
|
|
|
|
'single-list:{grains[roles]}': []
|
|
|
|
}
|
|
|
|
with patch('salt.utils.minions.get_minion_data',
|
|
|
|
MagicMock(return_value=(None, None, None))):
|
|
|
|
for case, correct_output in six.iteritems(cases):
|
|
|
|
test_config = {'policies': [case]}
|
|
|
|
output = vault._get_policies(minion_id, test_config) # pylint: disable=protected-access
|
|
|
|
diff = set(output).symmetric_difference(set(correct_output))
|
|
|
|
if len(diff) != 0:
|
|
|
|
log.debug('Test {0} failed'.format(case))
|
|
|
|
log.debug('Expected:\n\t{0}\nGot\n\t{1}'.format(output, correct_output))
|
|
|
|
log.debug('Difference:\n\t{0}'.format(diff))
|
|
|
|
self.assertEqual(output, correct_output)
|
|
|
|
|
2017-02-26 20:05:36 +00:00
|
|
|
@skipIf(NO_MOCK, NO_MOCK_REASON)
|
|
|
|
def test_get_policies(self):
|
|
|
|
'''
|
|
|
|
Ensure _get_policies works as intended, including expansion of lists
|
|
|
|
'''
|
|
|
|
cases = {
|
|
|
|
'no-tokens-to-replace': ['no-tokens-to-replace'],
|
|
|
|
'single-dict:{minion}': ['single-dict:test-minion'],
|
|
|
|
'single-list:{grains[roles]}': ['single-list:web', 'single-list:database'],
|
|
|
|
'multiple-lists:{grains[roles]}+{grains[aux]}': [
|
|
|
|
'multiple-lists:web+foo',
|
|
|
|
'multiple-lists:web+bar',
|
|
|
|
'multiple-lists:database+foo',
|
|
|
|
'multiple-lists:database+bar',
|
|
|
|
],
|
|
|
|
'single-list-with-dicts:{grains[id]}+{grains[roles]}+{grains[id]}': [
|
|
|
|
'single-list-with-dicts:test-minion+web+test-minion',
|
|
|
|
'single-list-with-dicts:test-minion+database+test-minion'
|
|
|
|
],
|
|
|
|
'deeply-nested-list:{grains[deep][foo][bar][baz]}': [
|
|
|
|
'deeply-nested-list:hello',
|
|
|
|
'deeply-nested-list:world'
|
2017-02-28 20:07:49 +00:00
|
|
|
],
|
2017-03-03 08:05:27 +00:00
|
|
|
'should-not-cause-an-exception,but-result-empty:{foo}': [],
|
|
|
|
'Case-Should-Be-Lowered:{grains[mixedcase]}': [
|
|
|
|
'case-should-be-lowered:up-low-up'
|
|
|
|
]
|
2017-02-26 20:05:36 +00:00
|
|
|
}
|
|
|
|
|
|
|
|
with patch('salt.utils.minions.get_minion_data',
|
|
|
|
MagicMock(return_value=(None, self.grains, None))):
|
|
|
|
for case, correct_output in six.iteritems(cases):
|
|
|
|
test_config = {'policies': [case]}
|
|
|
|
output = vault._get_policies('test-minion', test_config) # pylint: disable=protected-access
|
|
|
|
diff = set(output).symmetric_difference(set(correct_output))
|
|
|
|
if len(diff) != 0:
|
|
|
|
log.debug('Test {0} failed'.format(case))
|
|
|
|
log.debug('Expected:\n\t{0}\nGot\n\t{1}'.format(output, correct_output))
|
|
|
|
log.debug('Difference:\n\t{0}'.format(diff))
|
|
|
|
self.assertEqual(output, correct_output)
|