summaryrefslogtreecommitdiff
path: root/test/units/module_utils/test_known_hosts.py
diff options
context:
space:
mode:
authorWill Thames <will@thames.id.au>2017-02-16 05:47:57 +1000
committerToshio Kuratomi <a.badger@gmail.com>2017-02-15 13:51:08 -0800
commit60193bd8bcb4ca78637078ea79bcc66b4ae14c6c (patch)
tree6c65d4e1bcea7aa058d811bbcfdf8bc60a6388f7 /test/units/module_utils/test_known_hosts.py
parent1262e5fdca0bf4bef68a22c03f1afed80127ddfc (diff)
downloadansible-2.2-test.tar.gz
Ensure ssh hostkey checks respect server port (#20840)2.2-test
* Add tests for `get_fqdn_and_port` method. Currently tests verify original behavior - returning default `ssh-keyscan` port Add test around `add_host_key` to verify underlying command arguments Add some new expectations for `get_fqdn_and_port` Test that non-standard port is passed to `ssh-keyscan` command * Ensure ssh hostkey checks respect server port ssh-keyscan will default to getting the host key for port 22. If the ssh service is running on a different port, ssh-keyscan will need to know this. Tidy up minor flake8 issues * Update known_hosts tests for port being None Ensure that git urls don't try and set port when a path is specified Update known_hosts tests to meet flake8 * Fix stdin swap context for test_known_hosts Move test_known_hosts from under basic, as it is its own library. Remove module_utils.known_hosts from pep8 legacy files list (cherry picked from commit 103ede26dfe012cc2aef268ff97b73fd9b906c23)
Diffstat (limited to 'test/units/module_utils/test_known_hosts.py')
-rw-r--r--test/units/module_utils/test_known_hosts.py105
1 files changed, 105 insertions, 0 deletions
diff --git a/test/units/module_utils/test_known_hosts.py b/test/units/module_utils/test_known_hosts.py
new file mode 100644
index 0000000000..0bc8e55916
--- /dev/null
+++ b/test/units/module_utils/test_known_hosts.py
@@ -0,0 +1,105 @@
+# -*- coding: utf-8 -*-
+# (c) 2015, Michael Scherer <mscherer@redhat.com>
+#
+# This file is part of Ansible
+#
+# Ansible is free software: you can redistribute it and/or modify
+# it under the terms of the GNU General Public License as published by
+# the Free Software Foundation, either version 3 of the License, or
+# (at your option) any later version.
+#
+# Ansible is distributed in the hope that it will be useful,
+# but WITHOUT ANY WARRANTY; without even the implied warranty of
+# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+# GNU General Public License for more details.
+#
+# You should have received a copy of the GNU General Public License
+# along with Ansible. If not, see <http://www.gnu.org/licenses/>.
+
+from ansible.compat.tests import unittest
+from ansible.module_utils import known_hosts
+
+import json
+import ansible.module_utils.basic
+from ansible.compat.tests.mock import Mock
+from units.mock.procenv import swap_stdin_and_argv
+
+
+class TestAnsibleModuleKnownHosts(unittest.TestCase):
+ urls = {
+ 'ssh://one.example.org/example.git':
+ {'is_ssh_url': True, 'get_fqdn': 'one.example.org',
+ 'add_host_key_cmd': " -t rsa one.example.org",
+ 'port': None},
+ 'ssh+git://two.example.org/example.git':
+ {'is_ssh_url': True, 'get_fqdn': 'two.example.org',
+ 'add_host_key_cmd': " -t rsa two.example.org",
+ 'port': None},
+ 'rsync://three.example.org/user/example.git':
+ {'is_ssh_url': False, 'get_fqdn': 'three.example.org',
+ 'add_host_key_cmd': None, # not called for non-ssh urls
+ 'port': None},
+ 'git@four.example.org:user/example.git':
+ {'is_ssh_url': True, 'get_fqdn': 'four.example.org',
+ 'add_host_key_cmd': " -t rsa four.example.org",
+ 'port': None},
+ 'git+ssh://five.example.org/example.git':
+ {'is_ssh_url': True, 'get_fqdn': 'five.example.org',
+ 'add_host_key_cmd': " -t rsa five.example.org",
+ 'port': None},
+ 'ssh://six.example.org:21/example.org': # ssh on FTP Port?
+ {'is_ssh_url': True, 'get_fqdn': 'six.example.org',
+ 'add_host_key_cmd': " -t rsa -p 21 six.example.org",
+ 'port': '21'},
+ 'ssh://[2001:DB8::abcd:abcd]/example.git':
+ {'is_ssh_url': True, 'get_fqdn': '[2001:DB8::abcd:abcd]',
+ 'add_host_key_cmd': " -t rsa [2001:DB8::abcd:abcd]",
+ 'port': None},
+ 'ssh://[2001:DB8::abcd:abcd]:22/example.git':
+ {'is_ssh_url': True, 'get_fqdn': '[2001:DB8::abcd:abcd]',
+ 'add_host_key_cmd': " -t rsa -p 22 [2001:DB8::abcd:abcd]",
+ 'port': '22'},
+ 'username@[2001:DB8::abcd:abcd]/example.git':
+ {'is_ssh_url': True, 'get_fqdn': '[2001:DB8::abcd:abcd]',
+ 'add_host_key_cmd': " -t rsa [2001:DB8::abcd:abcd]",
+ 'port': None},
+ 'username@[2001:DB8::abcd:abcd]:path/example.git':
+ {'is_ssh_url': True, 'get_fqdn': '[2001:DB8::abcd:abcd]',
+ 'add_host_key_cmd': " -t rsa [2001:DB8::abcd:abcd]",
+ 'port': None},
+ 'ssh://internal.git.server:7999/repos/repo.git':
+ {'is_ssh_url': True, 'get_fqdn': 'internal.git.server',
+ 'add_host_key_cmd': " -t rsa -p 7999 internal.git.server",
+ 'port': '7999'}
+ }
+
+ def test_is_ssh_url(self):
+ for u in self.urls:
+ self.assertEqual(known_hosts.is_ssh_url(u), self.urls[u]['is_ssh_url'])
+
+ def test_get_fqdn_and_port(self):
+ for u in self.urls:
+ self.assertEqual(known_hosts.get_fqdn_and_port(u), (self.urls[u]['get_fqdn'], self.urls[u]['port']))
+
+ def test_add_host_key(self):
+
+ # Copied
+ args = json.dumps(dict(ANSIBLE_MODULE_ARGS={}))
+ # unittest doesn't have a clean place to use a context manager, so we have to enter/exit manually
+
+ with swap_stdin_and_argv(stdin_data=args):
+ ansible.module_utils.basic._ANSIBLE_ARGS = None
+ self.module = ansible.module_utils.basic.AnsibleModule(argument_spec=dict())
+
+ run_command = Mock()
+ run_command.return_value = (0, "Needs output, otherwise thinks ssh-keyscan timed out'", "")
+ self.module.run_command = run_command
+
+ get_bin_path = Mock()
+ get_bin_path.return_value = keyscan_cmd = "/custom/path/ssh-keyscan"
+ self.module.get_bin_path = get_bin_path
+
+ for u in self.urls:
+ if self.urls[u]['is_ssh_url']:
+ known_hosts.add_host_key(self.module, self.urls[u]['get_fqdn'], port=self.urls[u]['port'])
+ run_command.assert_called_with(keyscan_cmd + self.urls[u]['add_host_key_cmd'])