test_gpg.py 11 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273274275276277278279280281282283284285286287288289290291292293294295296297298299300301302303304305306307308309310
  1. # -*- coding: utf-8 -*-
  2. # Import Python Libs
  3. from __future__ import absolute_import, print_function, unicode_literals
  4. import os
  5. from subprocess import PIPE
  6. from textwrap import dedent
  7. # Import Salt libs
  8. import salt.renderers.gpg as gpg
  9. from salt.exceptions import SaltRenderError
  10. # Import Salt Testing libs
  11. from tests.support.mixins import (
  12. AdaptedConfigurationTestCaseMixin,
  13. LoaderModuleMockMixin,
  14. )
  15. from tests.support.mock import MagicMock, Mock, call, patch
  16. from tests.support.unit import TestCase
  17. class GPGTestCase(TestCase, LoaderModuleMockMixin, AdaptedConfigurationTestCaseMixin):
  18. """
  19. unit test GPG renderer
  20. """
  21. def setup_loader_modules(self):
  22. return {gpg: {}}
  23. def test__get_gpg_exec(self):
  24. """
  25. test _get_gpg_exec
  26. """
  27. gpg_exec = "/bin/gpg"
  28. with patch("salt.utils.path.which", MagicMock(return_value=gpg_exec)):
  29. self.assertEqual(gpg._get_gpg_exec(), gpg_exec)
  30. with patch("salt.utils.path.which", MagicMock(return_value=False)):
  31. self.assertRaises(SaltRenderError, gpg._get_gpg_exec)
  32. def test__decrypt_ciphertext(self):
  33. """
  34. test _decrypt_ciphertext
  35. """
  36. key_dir = "/etc/salt/gpgkeys"
  37. secret = "Use more salt."
  38. crypted = "-----BEGIN PGP MESSAGE-----!@#$%^&*()_+-----END PGP MESSAGE-----"
  39. multisecret = "password is {0} and salt is {0}".format(secret)
  40. multicrypted = "password is {0} and salt is {0}".format(crypted)
  41. class GPGDecrypt(object):
  42. def communicate(self, *args, **kwargs):
  43. return [secret, None]
  44. class GPGNotDecrypt(object):
  45. def communicate(self, *args, **kwargs):
  46. return [None, "decrypt error"]
  47. with patch(
  48. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  49. ), patch("salt.utils.path.which", MagicMock()):
  50. with patch(
  51. "salt.renderers.gpg.Popen", MagicMock(return_value=GPGDecrypt())
  52. ):
  53. self.assertEqual(gpg._decrypt_ciphertexts(crypted), secret)
  54. self.assertEqual(gpg._decrypt_ciphertexts(multicrypted), multisecret)
  55. with patch(
  56. "salt.renderers.gpg.Popen", MagicMock(return_value=GPGNotDecrypt())
  57. ):
  58. self.assertEqual(gpg._decrypt_ciphertexts(crypted), crypted)
  59. self.assertEqual(gpg._decrypt_ciphertexts(multicrypted), multicrypted)
  60. def test__decrypt_object(self):
  61. """
  62. test _decrypt_object
  63. """
  64. secret = "Use more salt."
  65. crypted = "-----BEGIN PGP MESSAGE-----!@#$%^&*()_+-----END PGP MESSAGE-----"
  66. secret_map = {"secret": secret}
  67. crypted_map = {"secret": crypted}
  68. secret_list = [secret]
  69. crypted_list = [crypted]
  70. with patch(
  71. "salt.renderers.gpg._decrypt_ciphertext", MagicMock(return_value=secret)
  72. ):
  73. self.assertEqual(gpg._decrypt_object(secret), secret)
  74. self.assertEqual(gpg._decrypt_object(crypted), secret)
  75. self.assertEqual(gpg._decrypt_object(crypted_map), secret_map)
  76. self.assertEqual(gpg._decrypt_object(crypted_list), secret_list)
  77. self.assertEqual(gpg._decrypt_object(None), None)
  78. def test_render(self):
  79. """
  80. test render
  81. """
  82. key_dir = "/etc/salt/gpgkeys"
  83. secret = "Use more salt."
  84. crypted = "-----BEGIN PGP MESSAGE-----!@#$%^&*()_+"
  85. with patch("salt.renderers.gpg._get_gpg_exec", MagicMock(return_value=True)):
  86. with patch(
  87. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  88. ):
  89. with patch(
  90. "salt.renderers.gpg._decrypt_object", MagicMock(return_value=secret)
  91. ):
  92. self.assertEqual(gpg.render(crypted), secret)
  93. def test_multi_render(self):
  94. key_dir = "/etc/salt/gpgkeys"
  95. secret = "Use more salt."
  96. expected = "\n".join([secret] * 3)
  97. crypted = dedent(
  98. """\
  99. -----BEGIN PGP MESSAGE-----
  100. !@#$%^&*()_+
  101. -----END PGP MESSAGE-----
  102. -----BEGIN PGP MESSAGE-----
  103. !@#$%^&*()_+
  104. -----END PGP MESSAGE-----
  105. -----BEGIN PGP MESSAGE-----
  106. !@#$%^&*()_+
  107. -----END PGP MESSAGE-----
  108. """
  109. )
  110. with patch("salt.renderers.gpg._get_gpg_exec", MagicMock(return_value=True)):
  111. with patch(
  112. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  113. ):
  114. with patch(
  115. "salt.renderers.gpg._decrypt_ciphertext",
  116. MagicMock(return_value=secret),
  117. ):
  118. self.assertEqual(gpg.render(crypted), expected)
  119. def test_render_with_binary_data_should_return_binary_data(self):
  120. key_dir = "/etc/salt/gpgkeys"
  121. secret = b"Use\x8b more\x8b salt."
  122. expected = b"\n".join([secret] * 3)
  123. crypted = dedent(
  124. """\
  125. -----BEGIN PGP MESSAGE-----
  126. !@#$%^&*()_+
  127. -----END PGP MESSAGE-----
  128. -----BEGIN PGP MESSAGE-----
  129. !@#$%^&*()_+
  130. -----END PGP MESSAGE-----
  131. -----BEGIN PGP MESSAGE-----
  132. !@#$%^&*()_+
  133. -----END PGP MESSAGE-----
  134. """
  135. )
  136. with patch("salt.renderers.gpg._get_gpg_exec", MagicMock(return_value=True)):
  137. with patch(
  138. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  139. ):
  140. with patch(
  141. "salt.renderers.gpg._decrypt_ciphertext",
  142. MagicMock(return_value=secret),
  143. ):
  144. self.assertEqual(gpg.render(crypted, encoding="utf-8"), expected)
  145. def test_render_with_translate_newlines_should_translate_newlines(self):
  146. key_dir = "/etc/salt/gpgkeys"
  147. secret = b"Use\x8b more\x8b salt."
  148. expected = b"\n\n".join([secret] * 3)
  149. crypted = dedent(
  150. """\
  151. -----BEGIN PGP MESSAGE-----
  152. !@#$%^&*()_+
  153. -----END PGP MESSAGE-----\\n
  154. -----BEGIN PGP MESSAGE-----
  155. !@#$%^&*()_+
  156. -----END PGP MESSAGE-----\\n
  157. -----BEGIN PGP MESSAGE-----
  158. !@#$%^&*()_+
  159. -----END PGP MESSAGE-----
  160. """
  161. )
  162. with patch("salt.renderers.gpg._get_gpg_exec", MagicMock(return_value=True)):
  163. with patch(
  164. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  165. ):
  166. with patch(
  167. "salt.renderers.gpg._decrypt_ciphertext",
  168. MagicMock(return_value=secret),
  169. ):
  170. self.assertEqual(
  171. gpg.render(crypted, translate_newlines=True, encoding="utf-8"),
  172. expected,
  173. )
  174. def test_render_without_cache(self):
  175. key_dir = "/etc/salt/gpgkeys"
  176. secret = "Use more salt."
  177. expected = "\n".join([secret] * 3)
  178. crypted = dedent(
  179. """\
  180. -----BEGIN PGP MESSAGE-----
  181. !@#$%^&*()_+
  182. -----END PGP MESSAGE-----
  183. -----BEGIN PGP MESSAGE-----
  184. !@#$%^&*()_+
  185. -----END PGP MESSAGE-----
  186. -----BEGIN PGP MESSAGE-----
  187. !@#$%^&*()_+
  188. -----END PGP MESSAGE-----
  189. """
  190. )
  191. with patch("salt.renderers.gpg.Popen") as popen_mock:
  192. popen_mock.return_value = Mock(
  193. communicate=lambda *args, **kwargs: (secret, None),
  194. )
  195. with patch(
  196. "salt.renderers.gpg._get_gpg_exec",
  197. MagicMock(return_value="/usr/bin/gpg"),
  198. ):
  199. with patch(
  200. "salt.renderers.gpg._get_key_dir", MagicMock(return_value=key_dir)
  201. ):
  202. self.assertEqual(gpg.render(crypted), expected)
  203. gpg_call = call(
  204. [
  205. "/usr/bin/gpg",
  206. "--homedir",
  207. "/etc/salt/gpgkeys",
  208. "--status-fd",
  209. "2",
  210. "--no-tty",
  211. "-d",
  212. ],
  213. shell=False,
  214. stderr=PIPE,
  215. stdin=PIPE,
  216. stdout=PIPE,
  217. )
  218. popen_mock.assert_has_calls([gpg_call] * 3)
  219. def test_render_with_cache(self):
  220. key_dir = "/etc/salt/gpgkeys"
  221. secret = "Use more salt."
  222. expected = "\n".join([secret] * 3)
  223. crypted = dedent(
  224. """\
  225. -----BEGIN PGP MESSAGE-----
  226. !@#$%^&*()_+
  227. -----END PGP MESSAGE-----
  228. -----BEGIN PGP MESSAGE-----
  229. !@#$%^&*()_+
  230. -----END PGP MESSAGE-----
  231. -----BEGIN PGP MESSAGE-----
  232. !@#$%^&*()_+
  233. -----END PGP MESSAGE-----
  234. """
  235. )
  236. minion_opts = self.get_temp_config("minion", gpg_cache=True)
  237. with patch.dict(gpg.__opts__, minion_opts):
  238. with patch("salt.renderers.gpg.Popen") as popen_mock:
  239. popen_mock.return_value = Mock(
  240. communicate=lambda *args, **kwargs: (secret, None),
  241. )
  242. with patch(
  243. "salt.renderers.gpg._get_gpg_exec",
  244. MagicMock(return_value="/usr/bin/gpg"),
  245. ):
  246. with patch(
  247. "salt.renderers.gpg._get_key_dir",
  248. MagicMock(return_value=key_dir),
  249. ):
  250. with patch(
  251. "salt.utils.atomicfile.atomic_open", MagicMock(),
  252. ) as atomic_open_mock:
  253. self.assertEqual(gpg.render(crypted), expected)
  254. gpg_call = call(
  255. [
  256. "/usr/bin/gpg",
  257. "--homedir",
  258. "/etc/salt/gpgkeys",
  259. "--status-fd",
  260. "2",
  261. "--no-tty",
  262. "-d",
  263. ],
  264. shell=False,
  265. stderr=PIPE,
  266. stdin=PIPE,
  267. stdout=PIPE,
  268. )
  269. popen_mock.assert_has_calls([gpg_call] * 1)
  270. atomic_open_mock.assert_has_calls(
  271. [
  272. call(
  273. os.path.join(
  274. minion_opts["cachedir"], "gpg_cache"
  275. ),
  276. "wb+",
  277. )
  278. ]
  279. )