testing: alice is RADIUS server in the ikev2/rw-eap-sim-radius scenario
[strongswan.git] / testing / do-tests
index f0b654a..f121019 100755 (executable)
 # or FITNESS FOR A PARTICULAR PURPOSE.  See the GNU General Public License
 # for more details.
 
-DIR=`dirname $0`
+DIR=$(dirname `readlink -f $0`)
+. $DIR/testing.conf
+. $DIR/scripts/function.sh
+SSHCONF="-F $DIR/ssh_config"
 
-source $DIR/scripts/function.sh
-
-[ -f $DIR/testing.conf ] || die "Configuration file 'testing.conf' not found"
 [ -d $DIR/hosts ] || die "Directory 'hosts' not found"
 [ -d $DIR/tests ] || die "Directory 'tests' not found"
+[ -d $BUILDDIR ] ||
+       die "Directory '$BUILDDIR' does not exist, please run make-testing first"
+running_any $STRONGSWANHOSTS || die "Please start test environment before running $0"
 
-source $DIR/testing.conf
-
-
-##############################################################################
-# test if UMLs have been built at all
-#
-
-[ -d $BUILDDIR ] || die "Directory '$BUILDDIR' does not exist. Please run 'make-testing'first."
-
+ln -sfT $DIR $TESTDIR/testing
 
 ##############################################################################
 # take care of new path and file variables
@@ -38,13 +33,13 @@ source $DIR/testing.conf
 
 [ -d $TESTRESULTSDIR ] || mkdir $TESTRESULTSDIR
 
-TESTDATE=`date +%Y%m%d-%H%M`
+TESTDATE=`date +%Y%m%d-%H%M-%S`
 
 TODAYDIR=$TESTRESULTSDIR/$TESTDATE
 mkdir $TODAYDIR
 TESTRESULTSHTML=$TODAYDIR/all.html
 INDEX=$TODAYDIR/index.html
-DEFAULTTESTSDIR=$UMLTESTDIR/testing/tests
+DEFAULTTESTSDIR=$TESTDIR/testing/tests
 
 SOURCEIP_ROUTING_TABLE=220
 
@@ -105,8 +100,9 @@ done
 #
 for host in $STRONGSWANHOSTS
 do
-    ssh $SSHCONF -N root@`eval echo \\\$ipv4_$host` &
+    ssh $SSHCONF -N root@`eval echo \\\$ipv4_$host` >/dev/null 2>&1 &
     eval ssh_pid_$host="`echo $!`"
+    do_on_exit kill `eval echo \\\$ssh_pid_$host`
 done
 
 
@@ -114,25 +110,22 @@ done
 # create header for the results html file
 #
 
-KERNEL_VERSION=`basename $KERNEL .tar.bz2`
-IPSEC_VERSION=`basename $STRONGSWAN .tar.bz2`
-
 ENVIRONMENT_HEADER=$(cat <<@EOF
-  <table border="0" cellspacing="2">
+  <table border="0" cellspacing="2" cellpadding="2">
     <tr valign="top">
-      <td><b>Host:</b></td>
+      <td><b>Host</b></td>
       <td colspan="3">`uname -a`</td>
     </tr>
     <tr valign="top">
-      <td><b>UML kernel: &nbsp;</b></td>
-      <td colspan="3">$KERNEL_VERSION</td>
+      <td><b>Guest kernel</b></td>
+      <td colspan="3">$KERNELVERSION</td>
     </tr>
     <tr valign="top">
-      <td><b>IPsec:</b></td>
-      <td colspan="3">$IPSEC_VERSION</td>
+      <td><b>strongSwan</b></td>
+      <td colspan="3">$SWANVERSION</td>
     </tr>
     <tr valign="top">
-      <td><b>Date:</b></td>
+      <td><b>Date</b></td>
       <td colspan="3">$TESTDATE</td>
     </tr>
     <tr>
@@ -147,20 +140,20 @@ ENVIRONMENT_HEADER=$(cat <<@EOF
 cat > $INDEX <<@EOF
 <html>
 <head>
-  <title>strongSwan UML Tests</title>
+  <title>strongSwan KVM Tests</title>
 </head>
 <body>
-  <h2>strongSwan UML Tests</h2>
+  <h2>strongSwan KVM Tests</h2>
   $ENVIRONMENT_HEADER
 @EOF
 
 cat > $TESTRESULTSHTML <<@EOF
 <html>
 <head>
-  <title>strongSwan UML Tests - All Tests</title>
+  <title>strongSwan KVM Tests - All Tests</title>
 </head>
 <body>
-  <div><a href="index.html">strongSwan UML Tests</a> / All Tests</div>
+  <div><a href="index.html">strongSwan KVM Tests</a> / All Tests</div>
   <h2>All Tests</h2>
   $ENVIRONMENT_HEADER
     <tr align="left">
@@ -170,10 +163,10 @@ cat > $TESTRESULTSHTML <<@EOF
     </tr>
 @EOF
 
-cecho "UML kernel: $KERNEL_VERSION"
-cecho "IPsec:      $IPSEC_VERSION"
-cecho "Date:       $TESTDATE"
-cecho ""
+echo "Guest kernel : $KERNELVERSION"
+echo "strongSwan   : $SWANVERSION"
+echo "Date         : $TESTDATE"
+echo
 
 
 ##############################################################################
@@ -183,10 +176,6 @@ cecho ""
 if [ $# -gt 0 ]
 then
     TESTS=$*
-elif [ $SELECTEDTESTSONLY = "yes" ]
-then
-    # set internal field seperator
-    TESTS=$SELECTEDTESTS
 else
     # set internal field seperator
     TESTS="`ls $DEFAULTTESTSDIR`"
@@ -208,7 +197,7 @@ do
        mkdir $TODAYDIR/$SUBDIR
        if [ $testnumber == 0 ]
        then
-           FIRST="<b>Category:</b>"
+           FIRST="<b>Category</b>"
        else
            FIRST="&nbsp;"
        fi
@@ -225,19 +214,19 @@ do
   <title>strongSwan $SUBDIR Tests</title>
 </head>
 <body>
-  <div><a href="../index.html">strongSwan UML Tests</a> / $SUBDIR</div>
+  <div><a href="../index.html">strongSwan KVM Tests</a> / $SUBDIR</div>
   <h2>strongSwan $SUBDIR Tests</h2>
-  <table border="0" cellspacing="2">
+  <table border="0" cellspacing="2" cellpadding="2">
     <tr valign="top">
-      <td><b>UML kernel: &nbsp;</b></td>
-      <td colspan="3">$KERNEL_VERSION</td>
+      <td><b>Guest kernel</b></td>
+      <td colspan="3">$KERNELVERSION</td>
     </tr>
     <tr valign="top">
-      <td><b>IPsec:</b></td>
-      <td colspan="3">$IPSEC_VERSION</td>
+      <td><b>strongSwan</b></td>
+      <td colspan="3">$SWANVERSION</td>
     </tr>
     <tr valign="top">
-      <td><b>Date:</b></td>
+      <td><b>Date</b></td>
       <td colspan="3">$TESTDATE</td>
     </tr>
     <tr>
@@ -258,35 +247,14 @@ do
     do
        let "testnumber += 1"
        testname=$SUBDIR/$name
-       cecho-n " $testnumber $testname.."
+       log_action " $testnumber $testname:"
 
        if [ ! -d $DEFAULTTESTSDIR/${testname} ]
        then
-           cecho "is missing..skipped"
+           echo "is missing..skipped"
            continue
        fi
 
-       if [ $SUBDIR = "ipv6" -o $name = "rw-psk-ipv6" ]
-       then
-           IPROUTE_CMD="ip -6 route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP=$IPROUTE_CMD
-           IPTABLES_CMD="ip6tables -v -n -L"
-           IPTABLES_DSP="ip6tables -L"
-       else
-           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP=$IPROUTE_CMD
-           IPTABLES_CMD="iptables -v -n -L"
-           IPTABLES_DSP="iptables -L"
-       fi
-
-       if [ $name = "net2net-ip4-in-ip6-ikev2" -o $name = "net2net-ip6-in-ip4-ikev2" ]
-       then
-           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE; echo; ip -6 route list table $SOURCEIP_ROUTING_TABLE"
-           IPROUTE_DSP="ip (-6) route list table $SOURCEIP_ROUTING_TABLE"
-           IPTABLES_CMD="iptables -v -n -L ; echo ; ip6tables -v -n -L"
-           IPTABLES_DSP="iptables -L ; ip6tables -L"
-       fi
-
        [ -f $DEFAULTTESTSDIR/${testname}/description.txt ] || die "!! File 'description.txt' is missing"
        [ -f $DEFAULTTESTSDIR/${testname}/test.conf ]       || die "!! File 'test.conf' is missing"
        [ -f $DEFAULTTESTSDIR/${testname}/pretest.dat ]     || die "!! File 'pretest.dat' is missing"
@@ -363,6 +331,8 @@ do
 
        $DIR/scripts/load-testconfig $testname
        unset RADIUSHOSTS
+       unset IPV6
+       unset SWANCTL
        source $TESTDIR/test.conf
 
 
@@ -385,12 +355,21 @@ do
            done
        fi
 
+       ##########################################################################
+       # flush conntrack table on all hosts
+       #
+
+       for host in $STRONGSWANHOSTS
+       do
+               ssh $SSHCONF root@`eval echo \\\$ipv4_$host` 'conntrack -F' >/dev/null 2>&1
+       done
+
 
        ##########################################################################
        # execute pre-test commands
        #
 
-       cecho-n "pre.."
+       echo -n "pre.."
        echo -e "\nPRE-TEST\n" >> $CONSOLE_LOG 2>&1
 
        eval `awk -F "::" '{
@@ -419,7 +398,7 @@ do
        # get and evaluate test results
        #
 
-       cecho-n "test.."
+       echo -n "test.."
        echo -e "\nTEST\n" >> $CONSOLE_LOG 2>&1
 
        STATUS="passed"
@@ -476,7 +455,7 @@ do
 <body>
 <table border="0" cellpadding="0" cellspacing="0" width="600">
   <tr><td>
-    <div><a href="../../index.html">strongSwan UML Tests</a> / <a href="../index.html">$SUBDIR</a> / $name</div>
+    <div><a href="../../index.html">strongSwan KVM Tests</a> / <a href="../index.html">$SUBDIR</a> / $name</div>
     <h2>Test $testname</h2>
     <h3>Description</h3>
 @EOF
@@ -487,27 +466,78 @@ do
     <ul>
       <li><a href="console.log">console.log</a></li>
     </ul>
-    <img src="../../images/$DIAGRAM" alt="$UMLHOSTS">
+    <img src="../../images/$DIAGRAM" alt="$VIRTHOSTS">
 @EOF
 
+       if [ -n "$IPV6" ]
+       then
+           IPROUTE_CMD="ip -6 route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP=$IPROUTE_CMD
+           IPTABLES_CMD="ip6tables -v -n -L"
+           IPTABLES_DSP="ip6tables -L"
+       else
+           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP=$IPROUTE_CMD
+           IPTABLES_CMD="iptables -v -n -L"
+           IPTABLES_DSP="iptables -L"
+       fi
+
+       if [ $name = "net2net-ip4-in-ip6-ikev2" -o $name = "net2net-ip6-in-ip4-ikev2" ]
+       then
+           IPROUTE_CMD="ip route list table $SOURCEIP_ROUTING_TABLE; echo; ip -6 route list table $SOURCEIP_ROUTING_TABLE"
+           IPROUTE_DSP="ip (-6) route list table $SOURCEIP_ROUTING_TABLE"
+           IPTABLES_CMD="iptables -v -n -L ; echo ; ip6tables -v -n -L"
+           IPTABLES_DSP="iptables -L ; ip6tables -L"
+       fi
+
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
 
-           for command in statusall listall
-           do
-               ssh $SSHCONF $HOSTLOGIN ipsec $command \
-                   > $TESTRESULTDIR/${host}.$command 2>/dev/null
-           done
+               scp $SSHCONF $HOSTLOGIN:/etc/strongswan.conf \
+                   $TESTRESULTDIR/${host}.strongswan.conf  > /dev/null 2>&1
 
-           for file in strongswan.conf ipsec.conf ipsec.secrets
-           do
-               scp $SSHCONF $HOSTLOGIN:/etc/$file \
-                   $TESTRESULTDIR/${host}.$file  > /dev/null 2>&1
-           done
+               if [  -n "$SWANCTL" ]
+               then
+                       scp $SSHCONF $HOSTLOGIN:/etc/swanctl/swanctl.conf \
+                       $TESTRESULTDIR/${host}.swanctl.conf  > /dev/null 2>&1
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-conns \
+                           > $TESTRESULTDIR/${host}.swanctl.conns 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-certs \
+                           > $TESTRESULTDIR/${host}.swanctl.certs 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-pools \
+                           > $TESTRESULTDIR/${host}.swanctl.pools 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-authorities \
+                           > $TESTRESULTDIR/${host}.swanctl.authorities 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-sas \
+                           > $TESTRESULTDIR/${host}.swanctl.sas 2>/dev/null
+
+                   ssh $SSHCONF $HOSTLOGIN swanctl --list-pols \
+                           > $TESTRESULTDIR/${host}.swanctl.pols 2>/dev/null
 
-           scp $SSHCONF $HOSTLOGIN:/etc/ipsec.d/ipsec.sql \
-               $TESTRESULTDIR/${host}.ipsec.sql  > /dev/null 2>&1
+                   ssh $SSHCONF $HOSTLOGIN swanctl --stats \
+                           > $TESTRESULTDIR/${host}.swanctl.stats 2>/dev/null
+               else
+                   for file in ipsec.conf ipsec.secrets
+                   do
+                               scp $SSHCONF $HOSTLOGIN:/etc/$file \
+                           $TESTRESULTDIR/${host}.$file  > /dev/null 2>&1
+                   done
+
+                   for command in statusall listall
+                   do
+                               ssh $SSHCONF $HOSTLOGIN ipsec $command \
+                           > $TESTRESULTDIR/${host}.$command 2>/dev/null
+                   done
+
+                   scp $SSHCONF $HOSTLOGIN:/etc/ipsec.d/ipsec.sql \
+                       $TESTRESULTDIR/${host}.ipsec.sql  > /dev/null 2>&1
+               fi
 
            ssh $SSHCONF $HOSTLOGIN ip -s xfrm policy \
                    > $TESTRESULTDIR/${host}.ip.policy 2>/dev/null
@@ -518,7 +548,47 @@ do
            ssh $SSHCONF $HOSTLOGIN $IPTABLES_CMD \
                    > $TESTRESULTDIR/${host}.iptables 2>/dev/null
            chmod a+r $TESTRESULTDIR/*
-           cat >> $TESTRESULTDIR/index.html <<@EOF
+
+               if [ -n "$SWANCTL" ]
+               then
+                   cat >> $TESTRESULTDIR/index.html <<@EOF
+    <h3>$host</h3>
+      <table border="0" cellspacing="0" width="600">
+      <tr>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.swanctl.conf">swanctl.conf</a></li>
+           <li><a href="$host.swanctl.conns">swanctl --list-conns</a></li>
+           <li><a href="$host.swanctl.certs">swanctl --list-certs</a></li>
+           <li><a href="$host.swanctl.pools">swanctl --list-pools</a></li>
+           <li><a href="$host.strongswan.conf">strongswan.conf</a></li>
+         </ul>
+       </td>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.swanctl.sas">swanctl --list-sas</a></li>
+           <li><a href="$host.swanctl.pols">swanctl --list-pols</a></li>
+           <li><a href="$host.swanctl.authorities">swanctl --list-authorities</a></li>
+           <li><a href="$host.swanctl.stats">swanctl --stats</a></li>
+           <li><a href="$host.daemon.log">daemon.log</a></li>
+         </ul>
+      </td>
+       <td valign="top">
+         <ul>
+           <li><a href="$host.ip.policy">ip -s xfrm policy</a></li>
+           <li><a href="$host.ip.state">ip -s xfrm state</a></li>
+           <li><a href="$host.ip.route">$IPROUTE_DSP</a></li>
+           <li><a href="$host.iptables">$IPTABLES_DSP</a></li>
+           <li><a href="$host.auth.log">auth.log</a></li>
+         </ul>
+         &nbsp;
+      </td>
+    </tr>
+    </table>
+@EOF
+
+               else
+                   cat >> $TESTRESULTDIR/index.html <<@EOF
     <h3>$host</h3>
       <table border="0" cellspacing="0" width="600">
       <tr>
@@ -549,7 +619,7 @@ do
     </tr>
     </table>
 @EOF
-
+               fi
        done
 
        for host in $RADIUSHOSTS
@@ -568,6 +638,9 @@ do
            scp $SSHCONF $HOSTLOGIN:/var/log/freeradius/radius.log \
                $TESTRESULTDIR/${host}.radius.log  > /dev/null 2>&1
 
+           ssh $SSHCONF $HOSTLOGIN grep imcv /var/log/daemon.log \
+               >> $TESTRESULTDIR/${host}.daemon.log 2>/dev/null
+
            chmod a+r $TESTRESULTDIR/*
            cat >> $TESTRESULTDIR/index.html <<@EOF
     <h3>$host</h3>
@@ -584,6 +657,7 @@ do
          <ul>
            <li><a href="$host.eap.conf">eap.conf</a></li>
            <li><a href="$host.radius.log">radius.log</a></li>
+           <li><a href="$host.daemon.log">daemon.log</a></li>
          </ul>
       </td>
        <td valign="top">
@@ -599,6 +673,28 @@ do
        done
 
        cat >> $TESTRESULTDIR/index.html <<@EOF
+       <h3>tcpdump</h3>
+       <ul>
+@EOF
+
+       for host in $TCPDUMPHOSTS
+       do
+           eval HOSTLOGIN=root@\$ipv4_${host}
+
+               scp $SSHCONF $HOSTLOGIN:/tmp/tcpdump.log \
+                       $TESTRESULTDIR/${host}.tcpdump.log > /dev/null 2>&1
+
+           cat >> $TESTRESULTDIR/index.html <<@EOF
+           <li><a href="$host.tcpdump.log">$host tcpdump.log</a></li>
+@EOF
+
+       done
+
+       cat >> $TESTRESULTDIR/index.html <<@EOF
+       </ul>
+@EOF
+
+       cat >> $TESTRESULTDIR/index.html <<@EOF
   </td></tr>
 </table>
 </body>
@@ -610,7 +706,7 @@ do
        # execute post-test commands
        #
 
-       cecho-n "post.."
+       echo -n "post"
        echo -e "\nPOST-TEST\n" >> $CONSOLE_LOG 2>&1
 
        eval `awk -F "::" '{
@@ -630,7 +726,7 @@ do
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
-           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated' \
+           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated|imcv|pt-tls-client' \
                /var/log/auth.log" >> $TESTRESULTDIR/${host}.auth.log
        done
 
@@ -642,7 +738,7 @@ do
        for host in $IPSECHOSTS
        do
            eval HOSTLOGIN=root@\$ipv4_${host}
-           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated' \
+           ssh $SSHCONF $HOSTLOGIN "grep -E 'charon|last message repeated|imcv' \
                /var/log/daemon.log" >> $TESTRESULTDIR/${host}.daemon.log
        done
 
@@ -675,11 +771,11 @@ do
 
        if [ $STATUS = "passed" ]
        then
-           COLOR="green"
-           cecho "\033[1;32m$STATUS"
+               COLOR="green"
+               log_status 0
        else
-           COLOR="red"
-           cecho "$STATUS"
+               COLOR="red"
+               log_status 1
        fi
 
        cat >> $TESTRESULTSHTML << @EOF
@@ -724,10 +820,10 @@ cat >> $TESTRESULTSHTML << @EOF
       <td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td><td>&nbsp;</td>
     </tr>
     <tr>
-      <td><b>Passed:</b></td><td><b><font color="green">$passed_cnt</font></b></td><td>&nbsp;</td><td>&nbsp;</td>
+      <td><b>Passed</b></td><td><b><font color="green">$passed_cnt</font></b></td><td>&nbsp;</td><td>&nbsp;</td>
     </tr>
     <tr>
-      <td><b>Failed:</b></td><td><b><font color="red">$failed_cnt</font></b></td><td>&nbsp;</td><td>&nbsp;</td>
+      <td><b>Failed</b></td><td><b><font color="red">$failed_cnt</font></b></td><td>&nbsp;</td><td>&nbsp;</td>
     </tr>
   </table>
 </body>
@@ -744,7 +840,7 @@ cat >> $INDEX << @EOF
       <td>&nbsp;</td>
     </tr>
     <tr>
-      <td><b>Failed:</b></td>
+      <td><b>Failed</b></td>
       <td>&nbsp;</td>
       <td align="right"><b><font color="red">$failed_cnt</font></b></td>
       <td>&nbsp;</td>
@@ -754,10 +850,10 @@ cat >> $INDEX << @EOF
 </html>
 @EOF
 
-cecho ""
-cecho "\033[1;32mPassed:   $passed_cnt"
-cecho "Failed:   $failed_cnt"
-cecho ""
+echo
+echo_ok     "Passed : $passed_cnt"
+echo_failed "Failed : $failed_cnt"
+echo
 
 
 ##############################################################################
@@ -766,20 +862,13 @@ cecho ""
 
 HTDOCS="/var/www"
 
-cecho-n "Copying test results to winnetou.."
 ssh $SSHCONF root@${ipv4_winnetou} mkdir -p $HTDOCS/testresults > /dev/null 2>&1
 scp $SSHCONF -r $TODAYDIR root@${ipv4_winnetou}:$HTDOCS/testresults > /dev/null 2>&1
 ssh $SSHCONF root@${ipv4_winnetou} ln -s $HTDOCS/images $HTDOCS/testresults/$TESTDATE/images > /dev/null 2>&1
-cgecho "done"
-cecho ""
-cecho "The results are available in $TODAYDIR"
-cecho "or via the link http://$ipv4_winnetou/testresults/$TESTDATE"
+echo
+echo "The results are available in $TODAYDIR"
+echo "or via the link http://$ipv4_winnetou/testresults/$TESTDATE"
 
-
-##########################################################################
-# close ssh sessions
-#
-for host in $STRONGSWANHOSTS
-do
-    kill `eval echo \\\$ssh_pid_$host`
-done
+ENDDATE=`date +%Y%m%d-%H%M`
+echo
+echo "Finished : $ENDDATE"