testing: alice is RADIUS server in the ikev2/rw-eap-sim-radius scenario
[strongswan.git] / testing / do-tests
index 49f8892..f121019 100755 (executable)
 DIR=$(dirname `readlink -f $0`)
 . $DIR/testing.conf
 . $DIR/scripts/function.sh
+SSHCONF="-F $DIR/ssh_config"
 
 [ -d $DIR/hosts ] || die "Directory 'hosts' not found"
 [ -d $DIR/tests ] || die "Directory 'tests' not found"
 [ -d $BUILDDIR ] ||
        die "Directory '$BUILDDIR' does not exist, please run make-testing first"
+running_any $STRONGSWANHOSTS || die "Please start test environment before running $0"
+
+ln -sfT $DIR $TESTDIR/testing
 
 ##############################################################################
 # take care of new path and file variables
@@ -29,7 +33,7 @@ DIR=$(dirname `readlink -f $0`)
 
 [ -d $TESTRESULTSDIR ] || mkdir $TESTRESULTSDIR
 
-TESTDATE=`date +%Y%m%d-%H%M`
+TESTDATE=`date +%Y%m%d-%H%M-%S`
 
 TODAYDIR=$TESTRESULTSDIR/$TESTDATE
 mkdir $TODAYDIR
@@ -136,20 +140,20 @@ ENVIRONMENT_HEADER=$(cat <<@EOF
 cat > $INDEX <<@EOF
 <html>
 <head>
-  <title>strongSwan UML Tests</title>
+  <title>strongSwan KVM Tests</title>
 </head>
 <body>
-  <h2>strongSwan UML Tests</h2>
+  <h2>strongSwan KVM Tests</h2>
   $ENVIRONMENT_HEADER
 @EOF
 
 cat > $TESTRESULTSHTML <<@EOF
 <html>
 <head>
-  <title>strongSwan UML Tests - All Tests</title>
+  <title>strongSwan KVM Tests - All Tests</title>
 </head>
 <body>
-  <div><a href="index.html">strongSwan UML Tests</a> / All Tests</div>
+  <div><a href="index.html">strongSwan KVM Tests</a> / All Tests</div>
   <h2>All Tests</h2>
   $ENVIRONMENT_HEADER
     <tr align="left">
@@ -210,11 +214,11 @@ do
   <title>strongSwan $SUBDIR Tests</title>
 </head>
 <body>
-  <div><a href="../index.html">strongSwan UML Tests</a> / $SUBDIR</div>
+  <div><a href="../index.html">strongSwan KVM Tests</a> / $SUBDIR</div>
   <h2>strongSwan $SUBDIR Tests</h2>
   <table border="0" cellspacing="2" cellpadding="2">
     <tr valign="top">
-      <td><b>UML kernel</b></td>
+      <td><b>Guest kernel</b></td>
       <td colspan="3">$KERNELVERSION</td>
     </tr>
     <tr valign="top">
@@ -251,27 +255,6 @@ do
            continue
        fi
 
-       if [ $SUBDIR = "ipv6" -o $name = "rw-psk-ipv6" ]
-       then
-           IPROUTE_CMD="ip -6 route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP=$IPROUTE_CMD
-           IPTABLES_CMD="ip6tables -v -n -L"
-           IPTABLES_DSP="ip6tables -L"
-       else
-           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP=$IPROUTE_CMD
-           IPTABLES_CMD="iptables -v -n -L"
-           IPTABLES_DSP="iptables -L"
-       fi
-
-       if [ $name = "net2net-ip4-in-ip6-ikev2" -o $name = "net2net-ip6-in-ip4-ikev2" ]
-       then
-           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE; echo; ip -6 route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP="ip (-6) route list table $SOURCEIP_ROUTING_TABLE"
-           IPTABLES_CMD="iptables -v -n -L ; echo ; ip6tables -v -n -L"
-           IPTABLES_DSP="iptables -L ; ip6tables -L"
-       fi
-
        [ -f $DEFAULTTESTSDIR/${testname}/description.txt ] || die "!! File 'description.txt' is missing"
        [ -f $DEFAULTTESTSDIR/${testname}/test.conf ]       || die "!! File 'test.conf' is missing"
        [ -f $DEFAULTTESTSDIR/${testname}/pretest.dat ]     || die "!! File 'pretest.dat' is missing"
@@ -348,6 +331,8 @@ do
 
        $DIR/scripts/load-testconfig $testname
        unset RADIUSHOSTS
+       unset IPV6
+       unset SWANCTL
        source $TESTDIR/test.conf
 
 
@@ -370,6 +355,15 @@ do
            done
        fi
 
+       ##########################################################################
+       # flush conntrack table on all hosts
+       #
+
+       for host in $STRONGSWANHOSTS
+       do
+               ssh $SSHCONF root@`eval echo \\\$ipv4_$host` 'conntrack -F' >/dev/null 2>&1
+       done
+
 
        ##########################################################################
        # execute pre-test commands
@@ -461,7 +455,7 @@ do
 <body>
 <table border="0" cellpadding="0" cellspacing="0" width="600">
   <tr><td>
-    <div><a href="../../index.html">strongSwan UML Tests</a> / <a href="../index.html">$SUBDIR</a> / $name</div>
+    <div><a href="../../index.html">strongSwan KVM Tests</a> / <a href="../index.html">$SUBDIR</a> / $name</div>
     <h2>Test $testname</h2>
     <h3>Description</h3>
 @EOF
@@ -472,27 +466,78 @@ do
     <ul>
       <li><a href="console.log">console.log</a></li>
     </ul>
-    <img src="../../images/$DIAGRAM" alt="$UMLHOSTS">
+    <img src="../../images/$DIAGRAM" alt="$VIRTHOSTS">
 @EOF
 
+       if [ -n "$IPV6" ]
+       then
+           IPROUTE_CMD="ip -6 route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP=$IPROUTE_CMD
+           IPTABLES_CMD="ip6tables -v -n -L"
+           IPTABLES_DSP="ip6tables -L"
+       else
+           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP=$IPROUTE_CMD
+           IPTABLES_CMD="iptables -v -n -L"
+           IPTABLES_DSP="iptables -L"
+       fi
+
+       if [ $name = "net2net-ip4-in-ip6-ikev2" -o $name = "net2net-ip6-in-ip4-ikev2" ]
+       then
+           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE; echo; ip -6 route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP="ip (-6) route list table $SOURCEIP_ROUTING_TABLE"
+           IPTABLES_CMD="iptables -v -n -L ; echo ; ip6tables -v -n -L"
+           IPTABLES_DSP="iptables -L ; ip6tables -L"
+       fi
+
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
 
-           for command in statusall listall
-           do
-               ssh $SSHCONF $HOSTLOGIN ipsec $command \
-                   > $TESTRESULTDIR/${host}.$command 2>/dev/null
-           done
+               scp $SSHCONF $HOSTLOGIN:/etc/strongswan.conf \
+                   $TESTRESULTDIR/${host}.strongswan.conf  > /dev/null 2>&1
 
-           for file in strongswan.conf ipsec.conf ipsec.secrets
-           do
-               scp $SSHCONF $HOSTLOGIN:/etc/$file \
-                   $TESTRESULTDIR/${host}.$file  > /dev/null 2>&1
-           done
+               if [  -n "$SWANCTL" ]
+               then
+                       scp $SSHCONF $HOSTLOGIN:/etc/swanctl/swanctl.conf \
+                       $TESTRESULTDIR/${host}.swanctl.conf  > /dev/null 2>&1
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-conns \
+                           > $TESTRESULTDIR/${host}.swanctl.conns 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-certs \
+                           > $TESTRESULTDIR/${host}.swanctl.certs 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-pools \
+                           > $TESTRESULTDIR/${host}.swanctl.pools 2>/dev/null
 
-           scp $SSHCONF $HOSTLOGIN:/etc/ipsec.d/ipsec.sql \
-               $TESTRESULTDIR/${host}.ipsec.sql  > /dev/null 2>&1
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-authorities \
+                           > $TESTRESULTDIR/${host}.swanctl.authorities 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-sas \
+                           > $TESTRESULTDIR/${host}.swanctl.sas 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-pols \
+                           > $TESTRESULTDIR/${host}.swanctl.pols 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --stats \
+                           > $TESTRESULTDIR/${host}.swanctl.stats 2>/dev/null
+               else
+                   for file in ipsec.conf ipsec.secrets
+                   do
+                               scp $SSHCONF $HOSTLOGIN:/etc/$file \
+                           $TESTRESULTDIR/${host}.$file  > /dev/null 2>&1
+                   done
+
+                   for command in statusall listall
+                   do
+                               ssh $SSHCONF $HOSTLOGIN ipsec $command \
+                           > $TESTRESULTDIR/${host}.$command 2>/dev/null
+                   done
+
+                   scp $SSHCONF $HOSTLOGIN:/etc/ipsec.d/ipsec.sql \
+                       $TESTRESULTDIR/${host}.ipsec.sql  > /dev/null 2>&1
+               fi
 
            ssh $SSHCONF $HOSTLOGIN ip -s xfrm policy \
                    > $TESTRESULTDIR/${host}.ip.policy 2>/dev/null
@@ -503,7 +548,47 @@ do
            ssh $SSHCONF $HOSTLOGIN $IPTABLES_CMD \
                    > $TESTRESULTDIR/${host}.iptables 2>/dev/null
            chmod a+r $TESTRESULTDIR/*
-           cat >> $TESTRESULTDIR/index.html <<@EOF
+
+               if [ -n "$SWANCTL" ]
+               then
+                   cat >> $TESTRESULTDIR/index.html <<@EOF
+    <h3>$host</h3>
+      <table border="0" cellspacing="0" width="600">
+      <tr>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.swanctl.conf">swanctl.conf</a></li>
+           <li><a href="$host.swanctl.conns">swanctl --list-conns</a></li>
+           <li><a href="$host.swanctl.certs">swanctl --list-certs</a></li>
+           <li><a href="$host.swanctl.pools">swanctl --list-pools</a></li>
+           <li><a href="$host.strongswan.conf">strongswan.conf</a></li>
+         </ul>
+       </td>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.swanctl.sas">swanctl --list-sas</a></li>
+           <li><a href="$host.swanctl.pols">swanctl --list-pols</a></li>
+           <li><a href="$host.swanctl.authorities">swanctl --list-authorities</a></li>
+           <li><a href="$host.swanctl.stats">swanctl --stats</a></li>
+           <li><a href="$host.daemon.log">daemon.log</a></li>
+         </ul>
+      </td>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.ip.policy">ip -s xfrm policy</a></li>
+           <li><a href="$host.ip.state">ip -s xfrm state</a></li>
+           <li><a href="$host.ip.route">$IPROUTE_DSP</a></li>
+           <li><a href="$host.iptables">$IPTABLES_DSP</a></li>
+           <li><a href="$host.auth.log">auth.log</a></li>
+         </ul>
+         &nbsp;
+      </td>
+    </tr>
+    </table>
+@EOF
+
+               else
+                   cat >> $TESTRESULTDIR/index.html <<@EOF
     <h3>$host</h3>
       <table border="0" cellspacing="0" width="600">
       <tr>
@@ -534,7 +619,7 @@ do
     </tr>
     </table>
 @EOF
-
+               fi
        done
 
        for host in $RADIUSHOSTS
@@ -554,7 +639,7 @@ do
                $TESTRESULTDIR/${host}.radius.log  > /dev/null 2>&1
 
            ssh $SSHCONF $HOSTLOGIN grep imcv /var/log/daemon.log \
-               >> $TESTRESULTDIR/${host}.daemon.log
+               >> $TESTRESULTDIR/${host}.daemon.log 2>/dev/null
 
            chmod a+r $TESTRESULTDIR/*
            cat >> $TESTRESULTDIR/index.html <<@EOF
@@ -641,7 +726,7 @@ do
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
-           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated' \
+           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated|imcv|pt-tls-client' \
                /var/log/auth.log" >> $TESTRESULTDIR/${host}.auth.log
        done
 
@@ -653,7 +738,7 @@ do
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
-           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated' \
+           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated|imcv' \
                /var/log/daemon.log" >> $TESTRESULTDIR/${host}.daemon.log
        done