1 # Unix SMB/CIFS implementation.
2 # Copyright (C) Jelmer Vernooij <jelmer@samba.org> 2007-2008
4 # This program is free software; you can redistribute it and/or modify
5 # it under the terms of the GNU General Public License as published by
6 # the Free Software Foundation; either version 3 of the License, or
7 # (at your option) any later version.
9 # This program is distributed in the hope that it will be useful,
10 # but WITHOUT ANY WARRANTY; without even the implied warranty of
11 # MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
12 # GNU General Public License for more details.
14 # You should have received a copy of the GNU General Public License
15 # along with this program. If not, see <http://www.gnu.org/licenses/>.
18 """Tests for samba.upgradeprovision."""
21 from samba
.upgradehelpers
import (usn_in_range
, dn_sort
,
22 get_diff_sds
, update_secrets
,
23 construct_existor_expr
)
25 from samba
.tests
.provision
import create_dummy_secretsdb
26 from samba
.tests
import TestCaseInTempDir
28 from ldb
import SCOPE_BASE
30 from samba
.dcerpc
import security
32 def dummymessage(a
=None, b
=None):
36 class UpgradeProvisionTestCase(TestCaseInTempDir
):
37 """Some simple tests for individual functions in the provisioning code.
39 def test_usn_in_range(self
):
40 range = [5, 25, 35, 55]
45 self
.assertFalse(usn_in_range(v
, range))
47 vals
= [5, 20, 25, 35, 36]
50 self
.assertTrue(usn_in_range(v
, range))
52 def test_dn_sort(self
):
53 # higher level comes after lower even if lexicographicaly closer
54 # ie dc=tata,dc=toto (2 levels), comes after dc=toto
55 # even if dc=toto is lexicographicaly after dc=tata, dc=toto
56 self
.assertEquals(dn_sort("dc=tata,dc=toto", "dc=toto"), 1)
57 self
.assertEquals(dn_sort("dc=zata", "dc=tata"), 1)
58 self
.assertEquals(dn_sort("dc=toto,dc=tata",
59 "cn=foo,dc=toto,dc=tata"), -1)
60 self
.assertEquals(dn_sort("cn=bar, dc=toto,dc=tata",
61 "cn=foo, dc=toto,dc=tata"), -1)
63 def test_get_diff_sds(self
):
64 domsid
= security
.dom_sid('S-1-5-21')
66 sddl
= "O:SAG:DUD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA)\
67 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)S:AI(AU;CIIDSA;WP;;;WD)"
68 sddl1
= "O:SAG:DUD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA)\
69 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)S:AI(AU;CIIDSA;WP;;;WD)"
70 sddl2
= "O:BAG:DUD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA)\
71 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)S:AI(AU;CIIDSA;WP;;;WD)"
72 sddl3
= "O:SAG:BAD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA)\
73 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)S:AI(AU;CIIDSA;WP;;;WD)"
74 sddl4
= "O:SAG:DUD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;BA)\
75 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)S:AI(AU;CIIDSA;WP;;;WD)"
76 sddl5
= "O:SAG:DUD:AI(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA)\
77 (A;CIID;RP LCLORC;;;AU)(A;CIID;RPWPCRCCDCLCLORCWOWDSDDTSW;;;SY)"
79 self
.assertEquals(get_diff_sds(security
.descriptor
.from_sddl(sddl
, domsid
),
80 security
.descriptor
.from_sddl(sddl1
, domsid
),
82 txt
= get_diff_sds(security
.descriptor
.from_sddl(sddl
, domsid
),
83 security
.descriptor
.from_sddl(sddl2
, domsid
),
85 self
.assertEquals(txt
, "\tOwner mismatch: SA (in ref) BA(in current)\n")
86 txt
= get_diff_sds(security
.descriptor
.from_sddl(sddl
, domsid
),
87 security
.descriptor
.from_sddl(sddl3
, domsid
),
89 self
.assertEquals(txt
, "\tGroup mismatch: DU (in ref) BA(in current)\n")
90 txt
= get_diff_sds(security
.descriptor
.from_sddl(sddl
, domsid
),
91 security
.descriptor
.from_sddl(sddl4
, domsid
),
93 txtmsg
= "\tPart dacl is different between reference and current here\
94 is the detail:\n\t\t(A;CIID;RPWPCRCCLCLORCWOWDSW;;;BA) ACE is not present in\
95 the reference\n\t\t(A;CIID;RPWPCRCCLCLORCWOWDSW;;;SA) ACE is not present in\
97 self
.assertEquals(txt
, txtmsg
)
98 txt
= get_diff_sds(security
.descriptor
.from_sddl(sddl
, domsid
),
99 security
.descriptor
.from_sddl(sddl5
, domsid
),
101 self
.assertEquals(txt
, "\tCurrent ACL hasn't a sacl part\n")
103 def test_construct_existor_expr(self
):
104 res
= construct_existor_expr([])
105 self
.assertEquals(res
, "")
107 res
= construct_existor_expr(["foo"])
108 self
.assertEquals(res
, "(|(foo=*))")
110 res
= construct_existor_expr(["foo", "bar"])
111 self
.assertEquals(res
, "(|(foo=*)(bar=*))")
114 class UpdateSecretsTests(samba
.tests
.TestCaseInTempDir
):
117 super(UpdateSecretsTests
, self
).setUp()
118 self
.referencedb
= create_dummy_secretsdb(
119 os
.path
.join(self
.tempdir
, "ref.ldb"))
121 def _getEmptyDb(self
):
122 return Ldb(os
.path
.join(self
.tempdir
, "secrets.ldb"))
124 def _getCurrentFormatDb(self
):
125 return create_dummy_secretsdb(
126 os
.path
.join(self
.tempdir
, "secrets.ldb"))
128 def test_trivial(self
):
129 # Test that updating an already up-to-date secretsdb works fine
130 self
.secretsdb
= self
._getCurrentFormatDb
()
131 self
.assertEquals(None,
132 update_secrets(self
.referencedb
, self
.secretsdb
, dummymessage
))
134 def test_update_modules(self
):
135 empty_db
= self
._getEmptyDb
()
136 update_secrets(self
.referencedb
, empty_db
, dummymessage
)
137 newmodules
= empty_db
.search(base
="@MODULES", scope
=SCOPE_BASE
)
138 refmodules
= self
.referencedb
.search(base
="@MODULES", scope
=SCOPE_BASE
)
139 self
.assertEquals(newmodules
.msgs
, refmodules
.msgs
)
142 for name
in ["ref.ldb", "secrets.ldb", "secrets.tdb", "secrets.tdb.bak", "secrets.ntdb"]:
143 path
= os
.path
.join(self
.tempdir
, name
)
144 if os
.path
.exists(path
):
146 super(UpdateSecretsTests
, self
).tearDown()