blob: e44778065f6ab35af2b6891ea0c96c137463cb7c [file] [log] [blame]
Damien Millerda1e4bd2007-10-26 15:35:54 +10001# $OpenBSD: test-exec.sh,v 1.30 2007/10/26 05:30:01 djm Exp $
Damien Miller38cd4352002-05-01 13:17:33 +10002# Placed in the Public Domain.
3
Damien Miller38cd4352002-05-01 13:17:33 +10004#SUDO=sudo
5
Darren Tuckerfeb6f7f2005-02-08 20:17:17 +11006# Unbreak GNU head(1)
7_POSIX2_VERSION=199209
8export _POSIX2_VERSION
9
Darren Tucker50c7db92005-03-09 10:02:55 +110010case `uname -s 2>/dev/null` in
11OSF1*)
12 BIN_SH=xpg4
13 export BIN_SH
14 ;;
15esac
16
Darren Tucker3b9c0ad2004-06-23 09:28:20 +100017if [ ! -z "$TEST_SSH_PORT" ]; then
18 PORT="$TEST_SSH_PORT"
19else
20 PORT=4242
21fi
22
Darren Tucker6d3921f2003-09-04 15:35:48 +100023if [ -x /usr/ucb/whoami ]; then
24 USER=`/usr/ucb/whoami`
Tim Rice23ee3592003-09-11 22:32:17 -070025elif whoami >/dev/null 2>&1; then
Darren Tucker6d3921f2003-09-04 15:35:48 +100026 USER=`whoami`
Damien Millere682cb02006-02-01 11:21:01 +110027elif logname >/dev/null 2>&1; then
28 USER=`logname`
Darren Tucker6d3921f2003-09-04 15:35:48 +100029else
30 USER=`id -un`
31fi
32
Damien Miller38cd4352002-05-01 13:17:33 +100033OBJ=$1
34if [ "x$OBJ" = "x" ]; then
35 echo '$OBJ not defined'
36 exit 2
37fi
38if [ ! -d $OBJ ]; then
39 echo "not a directory: $OBJ"
40 exit 2
41fi
42SCRIPT=$2
43if [ "x$SCRIPT" = "x" ]; then
44 echo '$SCRIPT not defined'
45 exit 2
46fi
47if [ ! -f $SCRIPT ]; then
48 echo "not a file: $SCRIPT"
49 exit 2
50fi
Tim Rice9ad7e0e2004-02-12 07:17:10 -080051if $TEST_SHELL -n $SCRIPT; then
Damien Miller38cd4352002-05-01 13:17:33 +100052 true
53else
54 echo "syntax error in $SCRIPT"
55 exit 2
56fi
57unset SSH_AUTH_SOCK
58
Darren Tuckera0f3ba72005-03-07 18:33:02 +110059SRC=`dirname ${SCRIPT}`
60
Damien Miller38cd4352002-05-01 13:17:33 +100061# defaults
62SSH=ssh
63SSHD=sshd
64SSHAGENT=ssh-agent
65SSHADD=ssh-add
66SSHKEYGEN=ssh-keygen
67SSHKEYSCAN=ssh-keyscan
68SFTP=sftp
69SFTPSERVER=/usr/libexec/openssh/sftp-server
Darren Tucker50433a92004-06-16 20:15:59 +100070SCP=scp
Damien Miller38cd4352002-05-01 13:17:33 +100071
72if [ "x$TEST_SSH_SSH" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110073 SSH="${TEST_SSH_SSH}"
Damien Miller38cd4352002-05-01 13:17:33 +100074fi
75if [ "x$TEST_SSH_SSHD" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110076 SSHD="${TEST_SSH_SSHD}"
Damien Miller38cd4352002-05-01 13:17:33 +100077fi
78if [ "x$TEST_SSH_SSHAGENT" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110079 SSHAGENT="${TEST_SSH_SSHAGENT}"
Damien Miller38cd4352002-05-01 13:17:33 +100080fi
81if [ "x$TEST_SSH_SSHADD" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110082 SSHADD="${TEST_SSH_SSHADD}"
Damien Miller38cd4352002-05-01 13:17:33 +100083fi
84if [ "x$TEST_SSH_SSHKEYGEN" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110085 SSHKEYGEN="${TEST_SSH_SSHKEYGEN}"
Damien Miller38cd4352002-05-01 13:17:33 +100086fi
87if [ "x$TEST_SSH_SSHKEYSCAN" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110088 SSHKEYSCAN="${TEST_SSH_SSHKEYSCAN}"
Damien Miller38cd4352002-05-01 13:17:33 +100089fi
90if [ "x$TEST_SSH_SFTP" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110091 SFTP="${TEST_SSH_SFTP}"
Damien Miller38cd4352002-05-01 13:17:33 +100092fi
93if [ "x$TEST_SSH_SFTPSERVER" != "x" ]; then
Darren Tucker03c907a2004-02-29 20:31:08 +110094 SFTPSERVER="${TEST_SSH_SFTPSERVER}"
Damien Miller38cd4352002-05-01 13:17:33 +100095fi
Darren Tucker50433a92004-06-16 20:15:59 +100096if [ "x$TEST_SSH_SCP" != "x" ]; then
97 SCP="${TEST_SSH_SCP}"
98fi
Damien Miller38cd4352002-05-01 13:17:33 +100099
Darren Tucker977a9d22004-06-25 13:45:18 +1000100# Path to sshd must be absolute for rexec
Darren Tucker114572f2005-08-23 23:32:05 +1000101case "$SSHD" in
102/*) ;;
103*) SSHD=`which sshd` ;;
104esac
Darren Tucker977a9d22004-06-25 13:45:18 +1000105
Darren Tuckera0f3ba72005-03-07 18:33:02 +1100106if [ "x$TEST_SSH_LOGFILE" = "x" ]; then
107 TEST_SSH_LOGFILE=/dev/null
108fi
109
Damien Miller38cd4352002-05-01 13:17:33 +1000110# these should be used in tests
Darren Tucker50433a92004-06-16 20:15:59 +1000111export SSH SSHD SSHAGENT SSHADD SSHKEYGEN SSHKEYSCAN SFTP SFTPSERVER SCP
112#echo $SSH $SSHD $SSHAGENT $SSHADD $SSHKEYGEN $SSHKEYSCAN $SFTP $SFTPSERVER $SCP
Damien Miller38cd4352002-05-01 13:17:33 +1000113
114# helper
Darren Tucker53c55f42003-09-04 15:16:56 +1000115echon()
116{
117 if [ "x`echo -n`" = "x" ]; then
118 echo -n "$@"
119 elif [ "x`echo '\c'`" = "x" ]; then
120 echo "$@\c"
121 else
122 fatal "Don't know how to echo without newline."
123 fi
124}
125
Tim Rice23ee3592003-09-11 22:32:17 -0700126have_prog()
127{
128 saved_IFS="$IFS"
129 IFS=":"
130 for i in $PATH
131 do
132 if [ -x $i/$1 ]; then
133 IFS="$saved_IFS"
134 return 0
135 fi
136 done
137 IFS="$saved_IFS"
138 return 1
139}
140
Damien Miller38cd4352002-05-01 13:17:33 +1000141cleanup ()
142{
143 if [ -f $PIDFILE ]; then
144 pid=`cat $PIDFILE`
145 if [ "X$pid" = "X" ]; then
146 echo no sshd running
147 else
148 if [ $pid -lt 2 ]; then
149 echo bad pid for ssd: $pid
150 else
151 $SUDO kill $pid
152 fi
153 fi
154 fi
155}
156
157trace ()
158{
Damien Millerda1e4bd2007-10-26 15:35:54 +1000159 echo "trace: $@" >>$TEST_SSH_LOGFILE
Damien Miller38cd4352002-05-01 13:17:33 +1000160 if [ "X$TEST_SSH_TRACE" = "Xyes" ]; then
Damien Millerda1e4bd2007-10-26 15:35:54 +1000161 echo "$@"
Damien Miller38cd4352002-05-01 13:17:33 +1000162 fi
163}
164
165verbose ()
166{
Damien Millerda1e4bd2007-10-26 15:35:54 +1000167 echo "verbose: $@" >>$TEST_SSH_LOGFILE
Damien Miller38cd4352002-05-01 13:17:33 +1000168 if [ "X$TEST_SSH_QUIET" != "Xyes" ]; then
Damien Millerda1e4bd2007-10-26 15:35:54 +1000169 echo "$@"
Damien Miller38cd4352002-05-01 13:17:33 +1000170 fi
171}
172
173
174fail ()
175{
Damien Millerda1e4bd2007-10-26 15:35:54 +1000176 echo "FAIL: $@" >>$TEST_SSH_LOGFILE
Damien Miller38cd4352002-05-01 13:17:33 +1000177 RESULT=1
Damien Millerda1e4bd2007-10-26 15:35:54 +1000178 echo "$@"
Damien Miller38cd4352002-05-01 13:17:33 +1000179}
180
181fatal ()
182{
Damien Millerda1e4bd2007-10-26 15:35:54 +1000183 echo "FATAL: $@" >>$TEST_SSH_LOGFILE
Darren Tucker53c55f42003-09-04 15:16:56 +1000184 echon "FATAL: "
Damien Miller38cd4352002-05-01 13:17:33 +1000185 fail "$@"
186 cleanup
187 exit $RESULT
188}
189
190RESULT=0
191PIDFILE=$OBJ/pidfile
192
193trap fatal 3 2
194
195# create server config
196cat << EOF > $OBJ/sshd_config
Darren Tucker0e6868e2004-06-16 20:36:16 +1000197 StrictModes no
Damien Miller38cd4352002-05-01 13:17:33 +1000198 Port $PORT
Damien Miller76be6b82006-01-31 21:59:01 +1100199 AddressFamily inet
Damien Miller38cd4352002-05-01 13:17:33 +1000200 ListenAddress 127.0.0.1
201 #ListenAddress ::1
202 PidFile $PIDFILE
203 AuthorizedKeysFile $OBJ/authorized_keys_%u
Darren Tuckerf899e6a2005-03-14 23:02:46 +1100204 LogLevel VERBOSE
Darren Tucker4c37ef02004-06-16 20:08:56 +1000205 AcceptEnv _XXX_TEST_*
206 AcceptEnv _XXX_TEST
Darren Tuckere7d05832004-06-16 20:22:22 +1000207 Subsystem sftp $SFTPSERVER
Damien Miller38cd4352002-05-01 13:17:33 +1000208EOF
209
Darren Tucker6223eea2004-06-23 09:25:02 +1000210if [ ! -z "$TEST_SSH_SSHD_CONFOPTS" ]; then
211 trace "adding sshd_config option $TEST_SSH_SSHD_CONFOPTS"
212 echo "$TEST_SSH_SSHD_CONFOPTS" >> $OBJ/sshd_config
213fi
214
Damien Miller38cd4352002-05-01 13:17:33 +1000215# server config for proxy connects
216cp $OBJ/sshd_config $OBJ/sshd_proxy
217
218# allow group-writable directories in proxy-mode
219echo 'StrictModes no' >> $OBJ/sshd_proxy
220
221# create client config
222cat << EOF > $OBJ/ssh_config
223Host *
224 Hostname 127.0.0.1
225 HostKeyAlias localhost-with-alias
226 Port $PORT
227 User $USER
228 GlobalKnownHostsFile $OBJ/known_hosts
229 UserKnownHostsFile $OBJ/known_hosts
230 RSAAuthentication yes
231 PubkeyAuthentication yes
232 ChallengeResponseAuthentication no
233 HostbasedAuthentication no
234 PasswordAuthentication no
Damien Miller38cd4352002-05-01 13:17:33 +1000235 BatchMode yes
236 StrictHostKeyChecking yes
237EOF
238
Darren Tucker6223eea2004-06-23 09:25:02 +1000239if [ ! -z "$TEST_SSH_SSH_CONFOPTS" ]; then
240 trace "adding ssh_config option $TEST_SSH_SSHD_CONFOPTS"
241 echo "$TEST_SSH_SSH_CONFOPTS" >> $OBJ/ssh_config
242fi
243
Damien Miller38cd4352002-05-01 13:17:33 +1000244rm -f $OBJ/known_hosts $OBJ/authorized_keys_$USER
245
246trace "generate keys"
247for t in rsa rsa1; do
248 # generate user key
249 rm -f $OBJ/$t
Darren Tuckerfaec5ca2005-11-24 23:18:54 +1100250 ${SSHKEYGEN} -b 1024 -q -N '' -t $t -f $OBJ/$t ||\
Damien Miller38cd4352002-05-01 13:17:33 +1000251 fail "ssh-keygen for $t failed"
252
253 # known hosts file for client
254 (
Darren Tucker53c55f42003-09-04 15:16:56 +1000255 echon 'localhost-with-alias,127.0.0.1,::1 '
Damien Miller38cd4352002-05-01 13:17:33 +1000256 cat $OBJ/$t.pub
257 ) >> $OBJ/known_hosts
258
259 # setup authorized keys
260 cat $OBJ/$t.pub >> $OBJ/authorized_keys_$USER
261 echo IdentityFile $OBJ/$t >> $OBJ/ssh_config
262
263 # use key as host key, too
264 $SUDO cp $OBJ/$t $OBJ/host.$t
265 echo HostKey $OBJ/host.$t >> $OBJ/sshd_config
266
267 # don't use SUDO for proxy connect
268 echo HostKey $OBJ/$t >> $OBJ/sshd_proxy
269done
270chmod 644 $OBJ/authorized_keys_$USER
271
272# create a proxy version of the client config
273(
274 cat $OBJ/ssh_config
Darren Tucker4b9ac332005-03-07 19:15:06 +1100275 echo proxycommand ${SUDO} sh ${SRC}/sshd-log-wrapper.sh ${SSHD} ${TEST_SSH_LOGFILE} -i -f $OBJ/sshd_proxy
Damien Miller38cd4352002-05-01 13:17:33 +1000276) > $OBJ/ssh_proxy
277
278# check proxy config
279${SSHD} -t -f $OBJ/sshd_proxy || fatal "sshd_proxy broken"
280
281start_sshd ()
282{
283 # start sshd
284 $SUDO ${SSHD} -f $OBJ/sshd_config -t || fatal "sshd_config broken"
Darren Tuckera0f3ba72005-03-07 18:33:02 +1100285 $SUDO ${SSHD} -f $OBJ/sshd_config -e >>$TEST_SSH_LOGFILE 2>&1
Damien Miller38cd4352002-05-01 13:17:33 +1000286
287 trace "wait for sshd"
288 i=0;
Darren Tucker6d3921f2003-09-04 15:35:48 +1000289 while [ ! -f $PIDFILE -a $i -lt 10 ]; do
Damien Miller38cd4352002-05-01 13:17:33 +1000290 i=`expr $i + 1`
291 sleep $i
292 done
293
294 test -f $PIDFILE || fatal "no sshd running on port $PORT"
295}
296
Damien Miller38cd4352002-05-01 13:17:33 +1000297# source test body
298. $SCRIPT
299
300# kill sshd
301cleanup
302if [ $RESULT -eq 0 ]; then
303 verbose ok $tid
304else
305 echo failed $tid
306fi
307exit $RESULT