mirror of
https://github.com/samba-team/samba.git
synced 2025-10-16 11:33:16 +03:00
At the moment CTDB_SOCKET can be used outside of test mode even though nobody should do this. So, no longer allow this. This means ensuring CTDB_TEST_MODE is set in the in the "clusteredmember" selftest environment, so that CTDB_SOCKET is respected there.. Details... The associated use of chown(2) and chmod(2), used to secure the socket in ctdb_daemon.c:ux_socket_bind(), potentially enables a symlink race attack. However, the chown(2) is currently not done in test mode, so restricting the use of CTDB_SOCKET to test mode solves the potential security issue. Also, sprinkle warnings about use of CTDB_TEST_MODE in appropriate places, just to attempt to limit unwanted behaviour. An alternative could be to use the socket file descriptor with fchown(2) and fchmod(2). However, these system calls are not well defined on sockets. Still, this was previously done in CTDB's early days (using the poorly documented method where they are allowed in Linux (only?) before calling bind(2)). It was removed (due to portability issues, via commitscf1056df94
and2da3fe1b17
) and replaced with the current post-bind chown(2) and chmod(2). I would like to remove the CTDB_SOCKET environment variable entirely, since setting CTDB_TEST_MODE and CTDB_BASE covers all reasonable test environments. However, I have a feeling that people use it for interactive testing, and that can still be done in CTDB_TEST_MODE. BUG: https://bugzilla.samba.org/show_bug.cgi?id=15921 Signed-off-by: Martin Schwenke <mschwenke@ddn.com> Reported-by: *GUIAR OQBA * <techokba@gmail.com> Reviewed-by: Volker Lendecke <vl@samba.org> Autobuild-User(master): Volker Lendecke <vl@samba.org> Autobuild-Date(master): Thu Sep 25 09:02:06 UTC 2025 on atb-devel-224
# vim: ft=rst This directory contains test scripts that are useful for running a bunch of tests all at once. There are two parts to this: * The test runner (selftest/selftest.pl) * The test formatter selftest.pl simply outputs subunit, which can then be formatted or analyzed by tools that understand the subunit protocol. One of these tools is format-subunit, which is used by default as part of "make test". Available testsuites ==================== The available testsuites are obtained from a script, usually source{3,4}/selftest/tests.py. This script should for each testsuite output the name of the test, the command to run and the environment that should be provided. Use the included "plantest" function to generate the required output. Testsuite behaviour =================== Exit code ------------ The testsuites should exit with a non-zero exit code if at least one test failed. Skipped tests should not influence the exit code. Output format ------------- Testsuites can simply use the exit code to indicate whether all of their tests have succeeded or one or more have failed. It is also possible to provide more granular information using the Subunit protocol. This protocol works by writing simple messages to standard output. Any messages that can not be interpreted by this protocol are considered comments for the last announced test. For a full description of the subunit protocol, see the README file in the subunit repository at http://github.com/testing-cabal/subunit. The following commands are Samba extensions to Subunit: start-testsuite ~~~~~~~~~~~~~~~ start-testsuite: name The testsuite name is used as prefix for all containing tests. skip-testsuite ~~~~~~~~~~~~~~ skip-testsuite: name Mark the testsuite with the specified name as skipped. testsuite-success ~~~~~~~~~~~~~~~~~ testsuite-success: name Indicate that the testsuite has succeeded successfully. testsuite-fail ~~~~~~~~~~~~~~ testsuite-fail: name Indicate that a testsuite has failed. Environments ============ Tests often need to run against a server with particular things set up, a "environment". This environment is provided by the test "target": Samba 3, Samba 4 or Windows. The environments are currently available include - none: No server set up, no variables set. - dc,s3dc: Domain controller set up. The following environment variables will be set: * USERNAME: Administrator user name * PASSWORD: Administrator password * DOMAIN: Domain name * REALM: Realm name * SERVER: DC host name * SERVER_IP: DC IPv4 address * SERVER_IPV6: DC IPv6 address * NETBIOSNAME: DC NetBIOS name * NETIOSALIAS: DC NetBIOS alias - member,s4member,s3member: Domain controller and member server that is joined to it set up. The following environment variables will be set: * USERNAME: Domain administrator user name * PASSWORD: Domain administrator password * DOMAIN: Domain name * REALM: Realm name * SERVER: Name of the member server See Samba.pm, Samba3.pm and Samba4.pm for the full list. Running tests ============= To run all the tests use:: make test To run a quicker subset run:: make quicktest To run a specific test, use this syntax:: make test TESTS=testname for example:: make test TESTS=samba4.BASE-DELETE