14-dynsec-plugin-invalid.py 5.3 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150
  1. #!/usr/bin/env python3
  2. # Check invalid inputs for plugin commands
  3. from mosq_test_helper import *
  4. import json
  5. import shutil
  6. def write_config(filename, port):
  7. with open(filename, 'w') as f:
  8. f.write("listener %d\n" % (port))
  9. f.write("allow_anonymous true\n")
  10. f.write("plugin ../../plugins/dynamic-security/mosquitto_dynamic_security.so\n")
  11. f.write("plugin_opt_config_file %d/dynamic-security.json\n" % (port))
  12. def command_check(sock, command_payload, expected_response, msg=""):
  13. command_packet = mosq_test.gen_publish(topic="$CONTROL/dynamic-security/v1", qos=0, payload=json.dumps(command_payload))
  14. sock.send(command_packet)
  15. response = json.loads(mosq_test.read_publish(sock))
  16. if response != expected_response:
  17. print(expected_response)
  18. print(response)
  19. if msg != "":
  20. print(msg)
  21. raise ValueError(response)
  22. def command_check_text(sock, command_payload, expected_response, msg=""):
  23. command_packet = mosq_test.gen_publish(topic="$CONTROL/dynamic-security/v1", qos=0, payload=command_payload)
  24. sock.send(command_packet)
  25. response = json.loads(mosq_test.read_publish(sock))
  26. if response != expected_response:
  27. print(expected_response)
  28. print(response)
  29. if msg != "":
  30. print(msg)
  31. raise ValueError(response)
  32. port = mosq_test.get_port()
  33. conf_file = os.path.basename(__file__).replace('.py', '.conf')
  34. write_config(conf_file, port)
  35. # ==========================================================================
  36. # Bad commands
  37. # ==========================================================================
  38. # Invalid JSON
  39. bad1_command = 'not json'
  40. bad1_response = {'responses': [{'command': 'Unknown command', 'error': 'Invalid/missing commands'}]}
  41. # No commands
  42. bad2_command = {}
  43. bad2_response = {'responses': [{'command': 'Unknown command', 'error': 'Invalid/missing commands'}]}
  44. # Commands not an array
  45. bad3_command = {'commands': 'test'}
  46. bad3_response = {'responses': [{'command': 'Unknown command', 'error': 'Invalid/missing commands'}]}
  47. # Empty commands array
  48. bad4_command = {'commands': []}
  49. bad4_response = {'responses': []}
  50. # Empty command
  51. bad5_command = {'commands': ['bad']}
  52. bad5_response = {'responses': [{'command': 'Unknown command', 'error': 'Command not an object'}]}
  53. # Bad array type
  54. bad6_command = {'commands': [{}]}
  55. bad6_response = {'responses': [{'command': 'Unknown command', 'error': 'Missing command'}]}
  56. # Bad command type
  57. bad7_command = {'commands': [{'command':6}]}
  58. bad7_response = {'responses': [{'command': 'Unknown command', 'error': 'Missing command'}]}
  59. # Bad correlationData type
  60. bad8_command = {'commands': [{'command':'command', 'correlationData':6}]}
  61. bad8_response = {'responses': [{'command': 'command', 'error': 'Invalid correlationData data type.'}]}
  62. # Unknown command
  63. bad9_command = {'commands': [{'command':'command'}]}
  64. bad9_response = {'responses': [{'command': 'command', 'error': 'Unknown command'}]}
  65. # ==========================================================================
  66. # setDefaultACLAccess
  67. # ==========================================================================
  68. # Missing actions array
  69. set_default1_command = {'commands': [{'command':'setDefaultACLAccess'}]}
  70. set_default1_response = {'responses': [{'command': 'setDefaultACLAccess', 'error': 'Missing/invalid actions array'}]}
  71. # Actions array not an array
  72. set_default2_command = {'commands': [{'command':'setDefaultACLAccess', 'actions':'bad'}]}
  73. set_default2_response = {'responses': [{'command': 'setDefaultACLAccess', 'error': 'Missing/invalid actions array'}]}
  74. rc = 1
  75. keepalive = 10
  76. connect_packet = mosq_test.gen_connect("ctrl-test", keepalive=keepalive, username="admin", password="admin")
  77. connack_packet = mosq_test.gen_connack(rc=0)
  78. mid = 2
  79. subscribe_packet = mosq_test.gen_subscribe(mid, "$CONTROL/dynamic-security/#", 1)
  80. suback_packet = mosq_test.gen_suback(mid, 1)
  81. try:
  82. os.mkdir(str(port))
  83. shutil.copyfile("dynamic-security-init.json", "%d/dynamic-security.json" % (port))
  84. except FileExistsError:
  85. pass
  86. broker = mosq_test.start_broker(filename=os.path.basename(__file__), use_conf=True, port=port)
  87. try:
  88. sock = mosq_test.do_client_connect(connect_packet, connack_packet, timeout=5, port=port)
  89. mosq_test.do_send_receive(sock, subscribe_packet, suback_packet, "suback")
  90. command_check(sock, bad1_command, bad1_response, "1")
  91. command_check(sock, bad2_command, bad2_response, "2")
  92. command_check(sock, bad3_command, bad3_response, "3")
  93. command_check(sock, bad4_command, bad4_response, "4")
  94. command_check(sock, bad5_command, bad5_response, "5")
  95. command_check(sock, bad6_command, bad6_response, "6")
  96. command_check(sock, bad7_command, bad7_response, "7")
  97. command_check(sock, bad8_command, bad8_response, "8")
  98. command_check(sock, bad9_command, bad9_response, "9")
  99. command_check(sock, set_default1_command, set_default1_response, "1")
  100. command_check(sock, set_default2_command, set_default2_response, "2")
  101. rc = 0
  102. sock.close()
  103. except mosq_test.TestError:
  104. pass
  105. finally:
  106. os.remove(conf_file)
  107. try:
  108. os.remove(f"{port}/dynamic-security.json")
  109. except FileNotFoundError:
  110. pass
  111. os.rmdir(f"{port}")
  112. broker.terminate()
  113. broker.wait()
  114. (stdo, stde) = broker.communicate()
  115. if rc:
  116. print(stde.decode('utf-8'))
  117. exit(rc)