diff options
author | Tim Smith <tsmith84@gmail.com> | 2020-06-05 00:21:58 -0700 |
---|---|---|
committer | Tim Smith <tsmith84@gmail.com> | 2020-06-05 00:22:43 -0700 |
commit | 41687b7de9f5c3d022bfc6f8293e33e80ce143db (patch) | |
tree | 163db7efde62f8eb2f2bd6c6468a66845c7691f2 /spec/unit/provider | |
parent | 8652dbd2221994938a8d58e5f66f091d460e26ee (diff) | |
download | chef-41687b7de9f5c3d022bfc6f8293e33e80ce143db.tar.gz |
Add specs and rename fingerprint -> short idzypper_repository
These aren't actually fingerprints. They're short key ids
https://futureboy.us/pgp.html#ShortKeyID
Signed-off-by: Tim Smith <tsmith@chef.io>
Diffstat (limited to 'spec/unit/provider')
-rw-r--r-- | spec/unit/provider/zypper_repository_spec.rb | 70 |
1 files changed, 60 insertions, 10 deletions
diff --git a/spec/unit/provider/zypper_repository_spec.rb b/spec/unit/provider/zypper_repository_spec.rb index 83ed83d297..f0686874e6 100644 --- a/spec/unit/provider/zypper_repository_spec.rb +++ b/spec/unit/provider/zypper_repository_spec.rb @@ -28,12 +28,40 @@ describe Chef::Provider::ZypperRepository do # Output of the command: # => gpg --with-fingerprint [FILE] - ZYPPER_GPG_FINGER = <<~EOF.freeze + ZYPPER_GPG_20 = <<~EOF.freeze pub 2048R/3DBDC284 2011-08-19 [expires: 2024-06-14] Key fingerprint = 573B FD6B 3D8F BC64 1079 A6AB ABF5 BD82 7BD9 BF62 uid nginx signing key <signing-key@nginx.com> EOF + # Output of the command: + # => gpg --import-options import-show --dry-run --import --with-colons [FILE] + ZYPPER_GPG_22 = <<~EOF.freeze + pub:-:2048:1:ABF5BD827BD9BF62:1313747554:1718374819::-:::scSC::::::23::0: + fpr:::::::::573BFD6B3D8FBC641079A6ABABF5BD827BD9BF62: + uid:-::::1466086904::F18C4DBBFCB45099ABB59088DB6B252FA7E9FB41::nginx signing key <signing-key@nginx.com>::::::::::0: + gpg: Total number processed: 1 + EOF + + # Output of the command: + # -> gpg --version + ZYPPER_GPG_VERSION = <<~EOF.freeze + gpg (GnuPG) 2.2.20 + libgcrypt 1.8.5 + Copyright (C) 2020 Free Software Foundation, Inc. + License GPLv3+: GNU GPL version 3 or later <https://gnu.org/licenses/gpl.html> + This is free software: you are free to change and redistribute it. + There is NO WARRANTY, to the extent permitted by law. + + Home: /Users/tsmith/.gnupg + Supported algorithms: + Pubkey: RSA, ELG, DSA, ECDH, ECDSA, EDDSA + Cipher: IDEA, 3DES, CAST5, BLOWFISH, AES, AES192, AES256, TWOFISH, + CAMELLIA128, CAMELLIA192, CAMELLIA256 + Hash: SHA1, RIPEMD160, SHA256, SHA384, SHA512, SHA224 + Compression: Uncompressed, ZIP, ZLIB, BZIP2 + EOF + let(:new_resource) { Chef::Resource::ZypperRepository.new("Nginx Repository") } let(:logger) { double("Mixlib::Log::Child").as_null_object } let(:provider) do @@ -48,8 +76,16 @@ describe Chef::Provider::ZypperRepository do double("shell_out", stdout: ZYPPER_RPM_KEYS, exitstatus: 0, error?: false) end - let(:gpg_finger) do - double("shell_out", stdout: ZYPPER_GPG_FINGER, exitstatus: 0, error?: false) + let(:gpg_20) do + double("shell_out", stdout: ZYPPER_GPG_20, exitstatus: 0, error?: false) + end + + let(:gpg_22) do + double("shell_out", stdout: ZYPPER_GPG_22, exitstatus: 0, error?: false) + end + + let(:gpg_ver) do + double("shell_out", stdout: ZYPPER_GPG_VERSION, exitstatus: 0, error?: false) end it "responds to load_current_resource" do @@ -96,24 +132,38 @@ describe Chef::Provider::ZypperRepository do describe "#key_installed?" do before do - expect(provider).to receive(:shell_out).with("rpm -qa gpg-pubkey*").and_return(rpm_key_finger) + expect(provider).to receive(:shell_out).with("/bin/rpm -qa gpg-pubkey*").and_return(rpm_key_finger) end it "returns true if the key is installed" do - expect(provider).to receive(:key_fingerprint).and_return("3dbdc284") + expect(provider).to receive(:short_key_id).and_return("3dbdc284") expect(provider.key_installed?("/foo/nginx.key")).to be_truthy end it "returns false if the key is not installed" do - expect(provider).to receive(:key_fingerprint).and_return("BOGUS") + expect(provider).to receive(:short_key_id).and_return("BOGUS") expect(provider.key_installed?("/foo/nginx.key")).to be_falsey end end - describe "#key_fingerprint" do - it "returns the key's fingerprint" do - expect(provider).to receive(:shell_out!).with("gpg --with-fingerprint /foo/nginx.key").and_return(gpg_finger) - expect(provider.key_fingerprint("/foo/nginx.key")).to eq("3dbdc284") + describe "#gpg_version" do + it "returns the gpg version by shelling out to gpg" do + expect(provider).to receive(:shell_out!).with("gpg --version").and_return(gpg_ver) + expect(provider.gpg_version).to eq(Gem::Version.new("2.2.20")) + end + end + + describe "#short_key_id" do + it "returns the short key ID via running a dry-run import on gpg 2.2+" do + expect(provider).to receive(:gpg_version).and_return(Gem::Version.new("2.2")) + expect(provider).to receive(:shell_out!).with("gpg --import-options import-show --dry-run --import --with-colons /foo/nginx.key").and_return(gpg_22) + expect(provider.short_key_id("/foo/nginx.key")).to eq("7bd9bf62") + end + + it "returns the short key ID via --with-fingerpint on gpg < 2.2" do + expect(provider).to receive(:gpg_version).and_return(Gem::Version.new("2.0")) + expect(provider).to receive(:shell_out!).with("gpg --with-fingerprint /foo/nginx.key").and_return(gpg_20) + expect(provider.short_key_id("/foo/nginx.key")).to eq("3dbdc284") end end |