1*cdebaff8SEnji Cooper# $NetBSD: t_tcpip.sh,v 1.18 2016/08/13 11:22:11 christos Exp $ 257718be8SEnji Cooper# 357718be8SEnji Cooper# Copyright (c) 2011 The NetBSD Foundation, Inc. 457718be8SEnji Cooper# All rights reserved. 557718be8SEnji Cooper# 657718be8SEnji Cooper# Redistribution and use in source and binary forms, with or without 757718be8SEnji Cooper# modification, are permitted provided that the following conditions 857718be8SEnji Cooper# are met: 957718be8SEnji Cooper# 1. Redistributions of source code must retain the above copyright 1057718be8SEnji Cooper# notice, this list of conditions and the following disclaimer. 1157718be8SEnji Cooper# 2. Redistributions in binary form must reproduce the above copyright 1257718be8SEnji Cooper# notice, this list of conditions and the following disclaimer in the 1357718be8SEnji Cooper# documentation and/or other materials provided with the distribution. 1457718be8SEnji Cooper# 1557718be8SEnji Cooper# THIS SOFTWARE IS PROVIDED BY THE NETBSD FOUNDATION, INC. AND CONTRIBUTORS 1657718be8SEnji Cooper# ``AS IS'' AND ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED 1757718be8SEnji Cooper# TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR 1857718be8SEnji Cooper# PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE FOUNDATION OR CONTRIBUTORS 1957718be8SEnji Cooper# BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR 2057718be8SEnji Cooper# CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF 2157718be8SEnji Cooper# SUBSTITUTE GOODS OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS 2257718be8SEnji Cooper# INTERRUPTION) HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN 2357718be8SEnji Cooper# CONTRACT, STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) 2457718be8SEnji Cooper# ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE 2557718be8SEnji Cooper# POSSIBILITY OF SUCH DAMAGE. 2657718be8SEnji Cooper# 2757718be8SEnji Cooper 28*cdebaff8SEnji Cooperrumpnetlibs="-lrumpnet -lrumpnet_net -lrumpnet_netinet6 -lrumpnet_netinet" 29*cdebaff8SEnji Cooperrumpnetsrv="rump_server $rumpnetlibs -lrumpdev" 3057718be8SEnji Cooperexport RUMP_SERVER=unix://csock 3157718be8SEnji Cooper 3257718be8SEnji Cooperatf_test_case http cleanup 3357718be8SEnji Cooperhttp_head() 3457718be8SEnji Cooper{ 3557718be8SEnji Cooper atf_set "descr" "Start hijacked httpd and get webpage from it" 3657718be8SEnji Cooper} 3757718be8SEnji Cooper 3857718be8SEnji Cooperhttp_body() 3957718be8SEnji Cooper{ 4057718be8SEnji Cooper 41*cdebaff8SEnji Cooper atf_check -s exit:0 ${rumpnetsrv} ${RUMP_SERVER} 4257718be8SEnji Cooper 4357718be8SEnji Cooper # start bozo in daemon mode 4457718be8SEnji Cooper atf_check -s exit:0 env LD_PRELOAD=/usr/lib/librumphijack.so \ 4557718be8SEnji Cooper /usr/libexec/httpd -P ./httpd.pid -b -s $(atf_get_srcdir) 4657718be8SEnji Cooper 4757718be8SEnji Cooper atf_check -s exit:0 -o file:"$(atf_get_srcdir)/netstat.expout" \ 4857718be8SEnji Cooper rump.netstat -a 4957718be8SEnji Cooper 5057718be8SEnji Cooper # get the webpage 5157718be8SEnji Cooper atf_check -s exit:0 env LD_PRELOAD=/usr/lib/librumphijack.so \ 5257718be8SEnji Cooper $(atf_get_srcdir)/h_netget 127.0.0.1 80 webfile 5357718be8SEnji Cooper 5457718be8SEnji Cooper # check that we got what we wanted 5557718be8SEnji Cooper atf_check -o match:'HTTP/1.0 200 OK' cat webfile 5657718be8SEnji Cooper atf_check -o match:'Content-Length: 95' cat webfile 57640235e2SEnji Cooper blank_line_re="$(printf '^\r$')" # matches a line with only <CR><LF> 5857718be8SEnji Cooper atf_check -o file:"$(atf_get_srcdir)/index.html" \ 59640235e2SEnji Cooper sed -n "1,/${blank_line_re}/!p" webfile 6057718be8SEnji Cooper} 6157718be8SEnji Cooper 6257718be8SEnji Cooperhttp_cleanup() 6357718be8SEnji Cooper{ 6457718be8SEnji Cooper if [ -f httpd.pid ]; then 6557718be8SEnji Cooper kill -9 "$(cat httpd.pid)" 6657718be8SEnji Cooper rm -f httpd.pid 6757718be8SEnji Cooper fi 6857718be8SEnji Cooper 6957718be8SEnji Cooper rump.halt 7057718be8SEnji Cooper} 7157718be8SEnji Cooper 7257718be8SEnji Cooper# 7357718be8SEnji Cooper# Starts a SSH server and sets up the client to access it. 7457718be8SEnji Cooper# Authentication is allowed and done using an RSA key exclusively, which 7557718be8SEnji Cooper# is generated on the fly as part of the test case. 7657718be8SEnji Cooper# XXX: Ideally, all the tests in this test program should be able to share 7757718be8SEnji Cooper# the generated key, because creating it can be a very slow process on some 7857718be8SEnji Cooper# machines. 7957718be8SEnji Cooper# 8057718be8SEnji Cooper# XXX2: copypasted from jmmv's sshd thingamob in the psshfs test. 8157718be8SEnji Cooper# ideally code (and keys, like jmmv notes above) could be shared 8257718be8SEnji Cooper# 8357718be8SEnji Cooperstart_sshd() { 8457718be8SEnji Cooper echo "Setting up SSH server configuration" 8557718be8SEnji Cooper sed -e "s,@SRCDIR@,$(atf_get_srcdir),g" -e "s,@WORKDIR@,$(pwd),g" \ 8657718be8SEnji Cooper $(atf_get_srcdir)/sshd_config.in >sshd_config || \ 8757718be8SEnji Cooper atf_fail "Failed to create sshd_config" 8857718be8SEnji Cooper atf_check -s ignore -o empty -e ignore \ 8957718be8SEnji Cooper cp $(atf_get_srcdir)/ssh_host_key . 9057718be8SEnji Cooper atf_check -s ignore -o empty -e ignore \ 9157718be8SEnji Cooper cp $(atf_get_srcdir)/ssh_host_key.pub . 9257718be8SEnji Cooper atf_check -s eq:0 -o empty -e empty chmod 400 ssh_host_key 9357718be8SEnji Cooper atf_check -s eq:0 -o empty -e empty chmod 444 ssh_host_key.pub 9457718be8SEnji Cooper 9557718be8SEnji Cooper env LD_PRELOAD=/usr/lib/librumphijack.so \ 9657718be8SEnji Cooper /usr/sbin/sshd -e -f ./sshd_config 9757718be8SEnji Cooper while [ ! -f sshd.pid ]; do 9857718be8SEnji Cooper sleep 0.01 9957718be8SEnji Cooper done 10057718be8SEnji Cooper echo "SSH server started (pid $(cat sshd.pid))" 10157718be8SEnji Cooper 10257718be8SEnji Cooper echo "Setting up SSH client configuration" 10357718be8SEnji Cooper atf_check -s eq:0 -o empty -e empty \ 10457718be8SEnji Cooper ssh-keygen -f ssh_user_key -t rsa -b 1024 -N "" -q 10557718be8SEnji Cooper atf_check -s eq:0 -o empty -e empty \ 10657718be8SEnji Cooper cp ssh_user_key.pub authorized_keys 10757718be8SEnji Cooper echo "127.0.0.1,localhost,::1 " \ 10857718be8SEnji Cooper "$(cat $(atf_get_srcdir)/ssh_host_key.pub)" >known_hosts || \ 10957718be8SEnji Cooper atf_fail "Failed to create known_hosts" 11057718be8SEnji Cooper atf_check -s eq:0 -o empty -e empty chmod 600 authorized_keys 11157718be8SEnji Cooper sed -e "s,@SRCDIR@,$(atf_get_srcdir),g" -e "s,@WORKDIR@,$(pwd),g" \ 11257718be8SEnji Cooper $(atf_get_srcdir)/ssh_config.in >ssh_config || \ 11357718be8SEnji Cooper atf_fail "Failed to create ssh_config" 11457718be8SEnji Cooper 11557718be8SEnji Cooper echo "sshd running" 11657718be8SEnji Cooper} 11757718be8SEnji Cooper 11857718be8SEnji Cooperatf_test_case ssh cleanup 11957718be8SEnji Cooperssh_head() 12057718be8SEnji Cooper{ 12157718be8SEnji Cooper atf_set "descr" "Test that hijacked ssh/sshd works" 12257718be8SEnji Cooper} 12357718be8SEnji Cooper 12457718be8SEnji Cooperssh_body() 12557718be8SEnji Cooper{ 126640235e2SEnji Cooper atf_expect_fail "PR lib/50174" 12757718be8SEnji Cooper 12857718be8SEnji Cooper atf_check -s exit:0 ${rumpnetsrv} ${RUMP_SERVER} 12957718be8SEnji Cooper # make sure clients die after we nuke the server 13057718be8SEnji Cooper export RUMPHIJACK_RETRYCONNECT='die' 13157718be8SEnji Cooper 13257718be8SEnji Cooper start_sshd 13357718be8SEnji Cooper 13457718be8SEnji Cooper # create some sort of directory for us to "ls" 13557718be8SEnji Cooper mkdir testdir 13657718be8SEnji Cooper cd testdir 13757718be8SEnji Cooper jot 11 | xargs touch 13857718be8SEnji Cooper jot 11 12 | xargs mkdir 13957718be8SEnji Cooper cd .. 14057718be8SEnji Cooper 14157718be8SEnji Cooper atf_check -s exit:0 -o save:ssh.out \ 14257718be8SEnji Cooper env LD_PRELOAD=/usr/lib/librumphijack.so \ 14357718be8SEnji Cooper ssh -T -F ssh_config 127.0.0.1 env BLOCKSIZE=512 \ 14457718be8SEnji Cooper ls -li $(pwd)/testdir 14557718be8SEnji Cooper atf_check -s exit:0 -o file:ssh.out env BLOCKSIZE=512 \ 14657718be8SEnji Cooper ls -li $(pwd)/testdir 14757718be8SEnji Cooper} 14857718be8SEnji Cooper 14957718be8SEnji Cooperssh_cleanup() 15057718be8SEnji Cooper{ 15157718be8SEnji Cooper rump.halt 15257718be8SEnji Cooper # sshd dies due to RUMPHIJACK_RETRYCONNECT=1d6 15357718be8SEnji Cooper} 15457718be8SEnji Cooper 15557718be8SEnji Coopertest_nfs() 15657718be8SEnji Cooper{ 15757718be8SEnji Cooper 15857718be8SEnji Cooper magicstr='wind in my hair' 15957718be8SEnji Cooper # create ffs file system we'll be serving from 16057718be8SEnji Cooper atf_check -s exit:0 -o ignore newfs -F -s 10000 ffs.img 16157718be8SEnji Cooper 16257718be8SEnji Cooper # start nfs kernel server. this is a mouthful 16357718be8SEnji Cooper export RUMP_SERVER=unix://serversock 16457718be8SEnji Cooper atf_check -s exit:0 rump_server $* ${RUMP_SERVER} 16557718be8SEnji Cooper 16657718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 create 16757718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 linkstr shmbus 16857718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 inet 10.1.1.1 16957718be8SEnji Cooper 17057718be8SEnji Cooper export RUMPHIJACK_RETRYCONNECT=die 17157718be8SEnji Cooper export LD_PRELOAD=/usr/lib/librumphijack.so 17257718be8SEnji Cooper 17357718be8SEnji Cooper atf_check -s exit:0 mkdir -p /rump/var/run 17457718be8SEnji Cooper atf_check -s exit:0 mkdir -p /rump/var/db 17557718be8SEnji Cooper atf_check -s exit:0 touch /rump/var/db/mountdtab 17657718be8SEnji Cooper atf_check -s exit:0 mkdir /rump/etc 17757718be8SEnji Cooper atf_check -s exit:0 mkdir /rump/export 17857718be8SEnji Cooper 17957718be8SEnji Cooper atf_check -s exit:0 -x \ 18057718be8SEnji Cooper 'echo "/export -noresvport -noresvmnt 10.1.1.100" | \ 18157718be8SEnji Cooper dd of=/rump/etc/exports 2> /dev/null' 18257718be8SEnji Cooper 183640235e2SEnji Cooper atf_check -s exit:0 rump.sysctl -q -w kern.module.autoload=1 184640235e2SEnji Cooper 18557718be8SEnji Cooper atf_check -s exit:0 -e ignore mount_ffs /dk /rump/export 18657718be8SEnji Cooper atf_check -s exit:0 -x "echo ${magicstr} > /rump/export/im_alive" 18757718be8SEnji Cooper 18857718be8SEnji Cooper # start rpcbind. we want /var/run/rpcbind.sock 18957718be8SEnji Cooper export RUMPHIJACK='blanket=/var/run,socket=all' 19057718be8SEnji Cooper atf_check -s exit:0 rpcbind 19157718be8SEnji Cooper 19257718be8SEnji Cooper # ok, then we want mountd in the similar fashion 19357718be8SEnji Cooper export RUMPHIJACK='blanket=/var/run:/var/db:/export,socket=all,path=/rump,vfs=all' 19457718be8SEnji Cooper atf_check -s exit:0 mountd /rump/etc/exports 19557718be8SEnji Cooper 19657718be8SEnji Cooper # finally, le nfschuck 19757718be8SEnji Cooper export RUMPHIJACK='blanket=/var/run,socket=all,vfs=all' 19857718be8SEnji Cooper atf_check -s exit:0 nfsd 19957718be8SEnji Cooper 20057718be8SEnji Cooper # 20157718be8SEnji Cooper # now, time for the client server and associated madness. 20257718be8SEnji Cooper # 20357718be8SEnji Cooper 20457718be8SEnji Cooper export RUMP_SERVER=unix://clientsock 20557718be8SEnji Cooper unset RUMPHIJACK 20657718be8SEnji Cooper unset LD_PRELOAD 20757718be8SEnji Cooper 20857718be8SEnji Cooper # at least the kernel server is easier 209640235e2SEnji Cooper atf_check -s exit:0 rump_server -lrumpvfs -lrumpnet -lrumpdev \ 21057718be8SEnji Cooper -lrumpnet_net -lrumpnet_netinet -lrumpnet_shmif -lrumpfs_nfs\ 21157718be8SEnji Cooper ${RUMP_SERVER} 21257718be8SEnji Cooper 21357718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 create 21457718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 linkstr shmbus 21557718be8SEnji Cooper atf_check -s exit:0 rump.ifconfig shmif0 inet 10.1.1.100 21657718be8SEnji Cooper 21757718be8SEnji Cooper export LD_PRELOAD=/usr/lib/librumphijack.so 21857718be8SEnji Cooper 21957718be8SEnji Cooper atf_check -s exit:0 mkdir /rump/mnt 22057718be8SEnji Cooper atf_check -s exit:0 mount_nfs 10.1.1.1:/export /rump/mnt 22157718be8SEnji Cooper 22257718be8SEnji Cooper atf_check -s exit:0 -o inline:"${magicstr}\n" cat /rump/mnt/im_alive 22357718be8SEnji Cooper atf_check -s exit:0 -o match:'.*im_alive$' ls -l /rump/mnt/im_alive 22457718be8SEnji Cooper} 22557718be8SEnji Cooper 22657718be8SEnji Cooper 22757718be8SEnji Cooperatf_test_case nfs cleanup 22857718be8SEnji Coopernfs_head() 22957718be8SEnji Cooper{ 23057718be8SEnji Cooper atf_set "descr" "Test hijacked nfsd and mount_nfs" 23157718be8SEnji Cooper} 23257718be8SEnji Cooper 23357718be8SEnji Coopernfs_body() 23457718be8SEnji Cooper{ 23557718be8SEnji Cooper test_nfs -lrumpvfs -lrumpdev -lrumpnet -lrumpnet_net \ 236640235e2SEnji Cooper -lrumpnet_netinet -lrumpnet_local -lrumpnet_shmif -lrumpdev \ 23757718be8SEnji Cooper -lrumpdev_disk -lrumpfs_ffs -lrumpfs_nfs -lrumpfs_nfsserver \ 23857718be8SEnji Cooper -d key=/dk,hostpath=ffs.img,size=host 23957718be8SEnji Cooper} 24057718be8SEnji Cooper 24157718be8SEnji Coopernfs_cleanup() 24257718be8SEnji Cooper{ 24357718be8SEnji Cooper RUMP_SERVER=unix://serversock rump.halt 2> /dev/null 24457718be8SEnji Cooper RUMP_SERVER=unix://clientsock rump.halt 2> /dev/null 24557718be8SEnji Cooper : 24657718be8SEnji Cooper} 24757718be8SEnji Cooper 24857718be8SEnji Cooperatf_test_case nfs_autoload cleanup 24957718be8SEnji Coopernfs_autoload_head() 25057718be8SEnji Cooper{ 25157718be8SEnji Cooper atf_set "descr" "Test hijacked nfsd with autoload from /stand" 25257718be8SEnji Cooper} 25357718be8SEnji Cooper 25457718be8SEnji Coopernfs_autoload_body() 25557718be8SEnji Cooper{ 25657718be8SEnji Cooper [ `uname -m` = "i386" ] || atf_skip "test currently valid only on i386" 25757718be8SEnji Cooper test_nfs -lrumpvfs -lrumpdev -lrumpnet -lrumpnet_net \ 258640235e2SEnji Cooper -lrumpnet_netinet -lrumpnet_local -lrumpnet_shmif -lrumpdev \ 25957718be8SEnji Cooper -lrumpdev_disk -d key=/dk,hostpath=ffs.img,size=host 26057718be8SEnji Cooper} 26157718be8SEnji Cooper 26257718be8SEnji Coopernfs_autoload_cleanup() 26357718be8SEnji Cooper{ 26457718be8SEnji Cooper nfs_cleanup 26557718be8SEnji Cooper} 26657718be8SEnji Cooper 26757718be8SEnji Cooperatf_init_test_cases() 26857718be8SEnji Cooper{ 26957718be8SEnji Cooper atf_add_test_case http 27057718be8SEnji Cooper atf_add_test_case ssh 27157718be8SEnji Cooper atf_add_test_case nfs 27257718be8SEnji Cooper atf_add_test_case nfs_autoload 27357718be8SEnji Cooper} 274