tests/krb5: Fix handling authdata with missing PAC
[Samba.git] / bootstrap / config.py
blob320a28e0f0008fc07cc847cfc77f8523f00df2b6
1 #!/usr/bin/env python3
3 # Copyright (C) Catalyst.Net Ltd 2019
5 # This program is free software; you can redistribute it and/or modify
6 # it under the terms of the GNU General Public License as published by
7 # the Free Software Foundation; either version 3 of the License, or
8 # (at your option) any later version.
10 # This program is distributed in the hope that it will be useful,
11 # but WITHOUT ANY WARRANTY; without even the implied warranty of
12 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
13 # GNU General Public License for more details.
15 # You should have received a copy of the GNU General Public License
16 # along with this program. If not, see <http://www.gnu.org/licenses/>.
18 """
19 Manage dependencies and bootstrap environments for Samba.
21 Config file for packages and templates.
23 Author: Joe Guo <joeg@catalyst.net.nz>
24 """
25 import os
26 from os.path import abspath, dirname, join
27 HERE = abspath(dirname(__file__))
28 # output dir for rendered files
29 OUT = join(HERE, 'generated-dists')
32 # pkgs with same name in all packaging systems
33 COMMON = [
34 'acl',
35 'attr',
36 'autoconf',
37 'binutils',
38 'bison',
39 'ccache',
40 'curl',
41 'chrpath',
42 'flex',
43 'gcc',
44 'gdb',
45 'git',
46 'gzip',
47 'hostname',
48 'htop',
49 'lcov',
50 'make',
51 'patch',
52 'perl',
53 'psmisc', # for pstree in test
54 'rng-tools',
55 'rsync',
56 'sed',
57 'sudo', # docker images has no sudo by default
58 'tar',
59 'tree',
60 'wget',
64 # define pkgs for all packaging systems in parallel
65 # make it easier to find missing ones
66 # use latest ubuntu and fedora as defaults
67 # deb, rpm, ...
68 PKGS = [
69 # NAME1-dev, NAME2-devel
70 ('lmdb-utils', 'lmdb'),
71 ('mingw-w64', 'mingw64-gcc'),
72 ('zlib1g-dev', 'zlib-devel'),
73 ('libbsd-dev', 'libbsd-devel'),
74 ('liburing-dev', 'liburing-devel'),
75 ('libarchive-dev', 'libarchive-devel'),
76 ('libblkid-dev', 'libblkid-devel'),
77 ('libcap-dev', 'libcap-devel'),
78 ('libacl1-dev', 'libacl-devel'),
79 ('libattr1-dev', 'libattr-devel'),
81 # libNAME1-dev, NAME2-devel
82 ('libpopt-dev', 'popt-devel'),
83 ('libreadline-dev', 'readline-devel'),
84 ('libjansson-dev', 'jansson-devel'),
85 ('liblmdb-dev', 'lmdb-devel'),
86 ('libncurses5-dev', 'ncurses-devel'),
87 # NOTE: Debian 7+ or Ubuntu 16.04+
88 ('libsystemd-dev', 'systemd-devel'),
89 ('libkrb5-dev', 'krb5-devel'),
90 ('libldap2-dev', 'openldap-devel'),
91 ('libcups2-dev', 'cups-devel'),
92 ('libpam0g-dev', 'pam-devel'),
93 ('libgpgme11-dev', 'gpgme-devel'),
94 # NOTE: Debian 8+ and Ubuntu 14.04+
95 ('libgnutls28-dev', 'gnutls-devel'),
96 ('libtasn1-bin', 'libtasn1-tools'),
97 ('libtasn1-dev', 'libtasn1-devel'),
98 ('', 'quota-devel'),
99 ('uuid-dev', 'libuuid-devel'),
100 ('libjs-jquery', ''),
101 ('libavahi-common-dev', 'avahi-devel'),
102 ('libdbus-1-dev', 'dbus-devel'),
103 ('libpcap-dev', 'libpcap-devel'),
104 ('libunwind-dev', 'libunwind-devel'), # for back trace
105 ('libglib2.0-dev', 'glib2-devel'),
106 ('libicu-dev', 'libicu-devel'),
107 ('heimdal-multidev', ''),
109 # NAME1, NAME2
110 # for debian, locales provide locale support with language packs
111 # ubuntu split language packs to language-pack-xx
112 # for centos, glibc-common provide locale support with language packs
113 # fedora split language packs to glibc-langpack-xx
114 ('locales', 'glibc-common'), # required for locale
115 ('language-pack-en', 'glibc-langpack-en'), # we need en_US.UTF-8
116 ('bind9utils', 'bind-utils'),
117 ('dnsutils', ''),
118 ('xsltproc', 'libxslt'),
119 ('krb5-user', ''),
120 ('krb5-config', ''),
121 ('krb5-kdc', 'krb5-server'),
122 ('apt-utils', 'yum-utils'),
123 ('pkg-config', 'pkgconfig'),
124 ('procps', 'procps-ng'), # required for the free cmd in tests
125 ('lsb-release', 'lsb-release'), # we need lsb_relase to show info
126 ('', 'rpcgen'), # required for test
127 # refer: https://fedoraproject.org/wiki/Changes/SunRPCRemoval
128 ('', 'libtirpc-devel'), # for <rpc/rpc.h> header on fedora
129 ('', 'libnsl2-devel'), # for <rpcsvc/yp_prot.h> header on fedora
130 ('', 'rpcsvc-proto-devel'), # for <rpcsvc/rquota.h> header
131 ('mawk', 'gawk'),
133 ('python3', 'python3'),
134 ('python3-cryptography', 'python3-cryptography'), # for krb5 tests
135 ('python3-dev', 'python3-devel'),
136 ('python3-dbg', ''),
137 ('python3-iso8601', ''),
138 ('python3-gpg', 'python3-gpg'), # defaults to ubuntu/fedora latest
139 ('python3-markdown', 'python3-markdown'),
140 ('python3-matplotlib', ''),
141 ('python3-dnspython', 'python3-dns'),
142 ('python3-pexpect', ''), # for wintest only
143 ('python3-pyasn1', 'python3-pyasn1'), # for krb5 tests
145 ('', 'libsemanage-python'),
146 ('', 'policycoreutils-python'),
148 # perl
149 ('libparse-yapp-perl', 'perl-Parse-Yapp'),
150 ('libjson-perl', 'perl-JSON-Parse'),
151 ('perl-modules', ''),
152 ('', 'perl-Archive-Tar'),
153 ('', 'perl-ExtUtils-MakeMaker'),
154 ('', 'perl-Test-Base'),
155 ('', 'perl-generators'),
156 ('', 'perl-interpreter'),
158 # fs
159 ('xfslibs-dev', 'xfsprogs-devel'), # for xfs quota support
160 ('', 'glusterfs-api-devel'),
161 ('glusterfs-common', 'glusterfs-devel'),
162 ('libcephfs-dev', 'libcephfs-devel'),
164 # misc
165 # @ means group for rpm, use fedora as rpm default
166 ('build-essential', '@development-tools'),
167 ('debhelper', ''),
168 # rpm has no pkg for docbook-xml
169 ('docbook-xml', 'docbook-dtds'),
170 ('docbook-xsl', 'docbook-style-xsl'),
171 ('', 'keyutils-libs-devel'),
172 ('', 'which'),
176 DEB_PKGS = COMMON + [pkg for pkg, _ in PKGS if pkg]
177 RPM_PKGS = COMMON + [pkg for _, pkg in PKGS if pkg]
179 GENERATED_MARKER = r"""
181 # This file is generated by 'bootstrap/template.py --render'
182 # See also bootstrap/config.py
187 APT_BOOTSTRAP = r"""
188 #!/bin/bash
189 {GENERATED_MARKER}
190 set -xueo pipefail
192 export DEBIAN_FRONTEND=noninteractive
193 apt-get -y update
195 apt-get -y install \
196 {pkgs}
198 apt-get -y autoremove
199 apt-get -y autoclean
200 apt-get -y clean
204 YUM_BOOTSTRAP = r"""
205 #!/bin/bash
206 {GENERATED_MARKER}
207 set -xueo pipefail
209 yum update -y
210 yum install -y epel-release
211 yum install -y yum-plugin-copr
212 yum copr enable -y sergiomb/SambaAD
213 yum update -y
215 yum install -y \
216 {pkgs}
218 yum clean all
220 if [ ! -f /usr/bin/python3 ]; then
221 ln -sf /usr/bin/python3.6 /usr/bin/python3
225 CENTOS8_YUM_BOOTSTRAP = r"""
226 #!/bin/bash
227 {GENERATED_MARKER}
228 set -xueo pipefail
230 yum update -y
231 yum install -y dnf-plugins-core
232 yum install -y epel-release
234 yum -v repolist all
235 yum config-manager --set-enabled PowerTools -y || \
236 yum config-manager --set-enabled powertools -y
237 yum config-manager --set-enabled Devel -y || \
238 yum config-manager --set-enabled devel -y
239 yum update -y
241 yum install -y \
242 --setopt=install_weak_deps=False \
243 {pkgs}
245 yum clean all
248 DNF_BOOTSTRAP = r"""
249 #!/bin/bash
250 {GENERATED_MARKER}
251 set -xueo pipefail
253 dnf update -y
255 dnf install -y \
256 --setopt=install_weak_deps=False \
257 {pkgs}
259 dnf clean all
262 ZYPPER_BOOTSTRAP = r"""
263 #!/bin/bash
264 {GENERATED_MARKER}
265 set -xueo pipefail
267 zypper --non-interactive refresh
268 zypper --non-interactive update
269 zypper --non-interactive install \
270 --no-recommends \
271 system-user-nobody \
272 {pkgs}
274 zypper --non-interactive clean
276 if [ -f /usr/lib/mit/bin/krb5-config ]; then
277 ln -sf /usr/lib/mit/bin/krb5-config /usr/bin/krb5-config
281 # A generic shell script to setup locale
282 LOCALE_SETUP = r"""
283 #!/bin/bash
284 {GENERATED_MARKER}
285 set -xueo pipefail
287 # refer to /usr/share/i18n/locales
288 INPUTFILE=en_US
289 # refer to /usr/share/i18n/charmaps
290 CHARMAP=UTF-8
291 # locale to generate in /usr/lib/locale
292 # glibc/localedef will normalize UTF-8 to utf8, follow the naming style
293 LOCALE=$INPUTFILE.utf8
295 # if locale is already correct, exit
296 ( locale | grep LC_ALL | grep -i $LOCALE ) && exit 0
298 # if locale not available, generate locale into /usr/lib/locale
299 if ! ( locale --all-locales | grep -i $LOCALE )
300 then
301 # no-archive means create its own dir
302 localedef --inputfile $INPUTFILE --charmap $CHARMAP --no-archive $LOCALE
305 # update locale conf and global env file
306 # set both LC_ALL and LANG for safe
308 # update conf for Debian family
309 FILE=/etc/default/locale
310 if [ -f $FILE ]
311 then
312 echo LC_ALL="$LOCALE" > $FILE
313 echo LANG="$LOCALE" >> $FILE
316 # update conf for RedHat family
317 FILE=/etc/locale.conf
318 if [ -f $FILE ]
319 then
320 # LC_ALL is not valid in this file, set LANG only
321 echo LANG="$LOCALE" > $FILE
324 # update global env file
325 FILE=/etc/environment
326 if [ -f $FILE ]
327 then
328 # append LC_ALL if not exist
329 grep LC_ALL $FILE || echo LC_ALL="$LOCALE" >> $FILE
330 # append LANG if not exist
331 grep LANG $FILE || echo LANG="$LOCALE" >> $FILE
336 DOCKERFILE = r"""
337 {GENERATED_MARKER}
338 FROM {docker_image}
340 # pass in with --build-arg while build
341 ARG SHA1SUM
342 RUN [ -n $SHA1SUM ] && echo $SHA1SUM > /sha1sum.txt
344 ADD *.sh /tmp/
345 # need root permission, do it before USER samba
346 RUN /tmp/bootstrap.sh && /tmp/locale.sh
348 # if ld.gold exists, force link it to ld
349 RUN set -x; LD=$(which ld); LD_GOLD=$(which ld.gold); test -x $LD_GOLD && ln -sf $LD_GOLD $LD && test -x $LD && echo "$LD is now $LD_GOLD"
351 # make test can not work with root, so we have to create a new user
352 RUN useradd -m -U -s /bin/bash samba && \
353 mkdir -p /etc/sudoers.d && \
354 echo "samba ALL=(ALL) NOPASSWD:ALL" > /etc/sudoers.d/samba
356 USER samba
357 WORKDIR /home/samba
358 # samba tests rely on this
359 ENV USER=samba LC_ALL=en_US.utf8 LANG=en_US.utf8
362 # Vagrantfile snippet for each dist
363 VAGRANTFILE_SNIPPET = r"""
364 config.vm.define "{name}" do |v|
365 v.vm.box = "{vagrant_box}"
366 v.vm.hostname = "{name}"
367 v.vm.provision :shell, path: "{name}/bootstrap.sh"
368 v.vm.provision :shell, path: "{name}/locale.sh"
372 # global Vagrantfile with snippets for all dists
373 VAGRANTFILE_GLOBAL = r"""
374 {GENERATED_MARKER}
376 Vagrant.configure("2") do |config|
377 config.ssh.insert_key = false
379 {vagrantfile_snippets}
385 DEB_DISTS = {
386 'debian10': {
387 'docker_image': 'debian:10',
388 'vagrant_box': 'debian/buster64',
389 'replace': {
390 'language-pack-en': '', # included in locales
391 'liburing-dev': '', # not available
394 'ubuntu1604': {
395 'docker_image': 'ubuntu:16.04',
396 'vagrant_box': 'ubuntu/xenial64',
397 'replace': {
398 'python-gpg': 'python-gpgme',
399 'python3-gpg': 'python3-gpgme',
400 'glusterfs-common': '',
401 'libcephfs-dev': '',
402 'liburing-dev': '', # not available
405 'ubuntu1804': {
406 'docker_image': 'ubuntu:18.04',
407 'vagrant_box': 'ubuntu/bionic64',
408 'replace': {
409 'liburing-dev': '', # not available
412 'ubuntu2004': {
413 'docker_image': 'ubuntu:20.04',
414 'vagrant_box': 'ubuntu/focal64',
415 'replace': {
416 'liburing-dev': '', # not available
422 RPM_DISTS = {
423 'centos7': {
424 'docker_image': 'centos:7',
425 'vagrant_box': 'centos/7',
426 'bootstrap': YUM_BOOTSTRAP,
427 'replace': {
428 'lsb-release': 'redhat-lsb',
429 'python3': 'python36',
430 'python3-cryptography': 'python36-cryptography',
431 'python3-devel': 'python36-devel',
432 'python3-dns': 'python36-dns',
433 'python3-pyasn1': 'python36-pyasn1',
434 'python3-gpg': 'python36-gpg',
435 'python3-iso8601' : 'python36-iso8601',
436 'python3-markdown': 'python36-markdown',
437 # although python36-devel is available
438 # after epel-release installed
439 # however, all other python3 pkgs are still python36-ish
440 'python2-gpg': 'pygpgme',
441 'python3-gpg': '', # no python3-gpg yet
442 '@development-tools': '"@Development Tools"', # add quotes
443 'glibc-langpack-en': '', # included in glibc-common
444 'glibc-locale-source': '', # included in glibc-common
445 # update perl core modules on centos
446 # fix: Can't locate Archive/Tar.pm in @INC
447 'perl': 'perl-core',
448 'rpcsvc-proto-devel': '',
449 'glusterfs-api-devel': '',
450 'glusterfs-devel': '',
451 'libcephfs-devel': '',
452 'gnutls-devel': 'compat-gnutls34-devel',
453 'liburing-devel': '', # not available
456 'centos8': {
457 'docker_image': 'centos:8',
458 'vagrant_box': 'centos/8',
459 'bootstrap': CENTOS8_YUM_BOOTSTRAP,
460 'replace': {
461 'lsb-release': 'redhat-lsb',
462 '@development-tools': '"@Development Tools"', # add quotes
463 'libsemanage-python': 'python3-libsemanage',
464 'lcov': '', # does not exist
465 'perl-JSON-Parse': '', # does not exist?
466 'perl-Test-Base': 'perl-Test-Simple',
467 'policycoreutils-python': 'python3-policycoreutils',
468 'liburing-devel': '', # not available yet, Add me back, once available!
471 'fedora31': {
472 'docker_image': 'fedora:31',
473 'vagrant_box': 'fedora/31-cloud-base',
474 'bootstrap': DNF_BOOTSTRAP,
475 'replace': {
476 'lsb-release': 'redhat-lsb',
477 'libsemanage-python': 'python3-libsemanage',
478 'policycoreutils-python': 'python3-policycoreutils',
481 'fedora32': {
482 'docker_image': 'fedora:32',
483 'vagrant_box': 'fedora/32-cloud-base',
484 'bootstrap': DNF_BOOTSTRAP,
485 'replace': {
486 'lsb-release': 'redhat-lsb',
487 'libsemanage-python': 'python3-libsemanage',
488 'policycoreutils-python': 'python3-policycoreutils',
491 'opensuse150': {
492 'docker_image': 'opensuse/leap:15.0',
493 'vagrant_box': 'opensuse/openSUSE-15.0-x86_64',
494 'bootstrap': ZYPPER_BOOTSTRAP,
495 'replace': {
496 '@development-tools': '',
497 'dbus-devel': 'dbus-1-devel',
498 'docbook-style-xsl': 'docbook-xsl-stylesheets',
499 'glibc-common': 'glibc-locale',
500 'glibc-locale-source': 'glibc-i18ndata',
501 'glibc-langpack-en': '',
502 'jansson-devel': 'libjansson-devel',
503 'keyutils-libs-devel': 'keyutils-devel',
504 'krb5-workstation': 'krb5-client',
505 'libnsl2-devel': 'libnsl-devel',
506 'libsemanage-python': 'python2-semanage',
507 'openldap-devel': 'openldap2-devel',
508 'perl-Archive-Tar': 'perl-Archive-Tar-Wrapper',
509 'perl-JSON-Parse': 'perl-JSON-XS',
510 'perl-generators': '',
511 'perl-interpreter': '',
512 'procps-ng': 'procps',
513 'python-dns': 'python2-dnspython',
514 'python3-dns': 'python3-dnspython',
515 'python3-markdown': 'python3-Markdown',
516 'quota-devel': '',
517 'glusterfs-api-devel': '',
518 'libtasn1-tools': '', # asn1Parser is part of libtasn1
519 'mingw64-gcc': '', # doesn't exist
520 'liburing-devel': '', # not available
523 'opensuse151': {
524 'docker_image': 'opensuse/leap:15.1',
525 'vagrant_box': 'opensuse/openSUSE-15.1-x86_64',
526 'bootstrap': ZYPPER_BOOTSTRAP,
527 'replace': {
528 '@development-tools': '',
529 'dbus-devel': 'dbus-1-devel',
530 'docbook-style-xsl': 'docbook-xsl-stylesheets',
531 'glibc-common': 'glibc-locale',
532 'glibc-locale-source': 'glibc-i18ndata',
533 'glibc-langpack-en': '',
534 'jansson-devel': 'libjansson-devel',
535 'keyutils-libs-devel': 'keyutils-devel',
536 'krb5-workstation': 'krb5-client',
537 'libnsl2-devel': 'libnsl-devel',
538 'libsemanage-python': 'python2-semanage',
539 'openldap-devel': 'openldap2-devel',
540 'perl-Archive-Tar': 'perl-Archive-Tar-Wrapper',
541 'perl-JSON-Parse': 'perl-JSON-XS',
542 'perl-generators': '',
543 'perl-interpreter': '',
544 'procps-ng': 'procps',
545 'python-dns': 'python2-dnspython',
546 'python3-dns': 'python3-dnspython',
547 'python3-markdown': 'python3-Markdown',
548 'quota-devel': '',
549 'glusterfs-api-devel': '',
550 'libtasn1-tools': '', # asn1Parser is part of libtasn1
551 'mingw64-gcc': '', # doesn't exist
552 'liburing-devel': '', # not available, will be added in 15.2
558 DEB_FAMILY = {
559 'name': 'deb',
560 'pkgs': DEB_PKGS,
561 'bootstrap': APT_BOOTSTRAP, # family default
562 'dists': DEB_DISTS,
566 RPM_FAMILY = {
567 'name': 'rpm',
568 'pkgs': RPM_PKGS,
569 'bootstrap': YUM_BOOTSTRAP, # family default
570 'dists': RPM_DISTS,
574 YML_HEADER = r"""
576 packages:
580 def expand_family_dists(family):
581 dists = {}
582 for name, config in family['dists'].items():
583 config = config.copy()
584 config['name'] = name
585 config['home'] = join(OUT, name)
586 config['family'] = family['name']
587 config['GENERATED_MARKER'] = GENERATED_MARKER
589 # replace dist specific pkgs
590 replace = config.get('replace', {})
591 pkgs = []
592 for pkg in family['pkgs']:
593 pkg = replace.get(pkg, pkg) # replace if exists or get self
594 if pkg:
595 pkgs.append(pkg)
596 pkgs.sort()
598 lines = [' - {}'.format(pkg) for pkg in pkgs]
599 config['packages.yml'] = YML_HEADER.lstrip() + os.linesep.join(lines)
601 sep = ' \\' + os.linesep + ' '
602 config['pkgs'] = sep.join(pkgs)
604 # get dist bootstrap template or fall back to family default
605 bootstrap_template = config.get('bootstrap', family['bootstrap'])
606 config['bootstrap.sh'] = bootstrap_template.format(**config).strip()
607 config['locale.sh'] = LOCALE_SETUP.format(**config).strip()
609 config['Dockerfile'] = DOCKERFILE.format(**config).strip()
610 # keep the indent, no strip
611 config['vagrantfile_snippet'] = VAGRANTFILE_SNIPPET.format(**config)
613 dists[name] = config
614 return dists
617 # expanded config for dists
618 DEB_DISTS_EXP = expand_family_dists(DEB_FAMILY)
619 RPM_DISTS_EXP = expand_family_dists(RPM_FAMILY)
621 # assemble all together
622 DISTS = {}
623 DISTS.update(DEB_DISTS_EXP)
624 DISTS.update(RPM_DISTS_EXP)
627 def render_vagrantfile(dists):
629 Render all snippets for each dist into global Vagrantfile.
631 Vagrant supports multiple vms in one Vagrantfile.
632 This make it easier to manage the fleet, e.g:
634 start all: vagrant up
635 start one: vagrant up ubuntu1804
637 All other commands apply to above syntax, e.g.: status, destroy, provision
639 # sort dists by name and put all vagrantfile snippets together
640 snippets = [
641 dists[dist]['vagrantfile_snippet']
642 for dist in sorted(dists.keys())]
644 return VAGRANTFILE_GLOBAL.format(
645 vagrantfile_snippets=''.join(snippets),
646 GENERATED_MARKER=GENERATED_MARKER
650 VAGRANTFILE = render_vagrantfile(DISTS)
653 # data we need to expose
654 __all__ = ['DISTS', 'VAGRANTFILE', 'OUT']