Home | History | Annotate | Line # | Download | only in scripts
      1 #! /bin/sh
      2 # $OpenLDAP$
      3 ## This work is part of OpenLDAP Software <http://www.openldap.org/>.
      4 ##
      5 ## Copyright 1998-2024 The OpenLDAP Foundation.
      6 ## All rights reserved.
      7 ##
      8 ## Redistribution and use in source and binary forms, with or without
      9 ## modification, are permitted only as authorized by the OpenLDAP
     10 ## Public License.
     11 ##
     12 ## A copy of this license is available in the file LICENSE in the
     13 ## top-level directory of the distribution or, alternatively, at
     14 ## <http://www.OpenLDAP.org/license.html>.
     15 
     16 echo "running defines.sh"
     17 . $SRCDIR/scripts/defines.sh
     18 
     19 if test $WITH_TLS = no ; then
     20         echo "TLS support not available, test skipped"
     21         exit 0
     22 fi
     23 
     24 if test $SYNCPROV = syncprovno; then
     25 	echo "Syncrepl provider overlay not available, test skipped"
     26 	exit 0
     27 fi
     28 if test $ACCESSLOG = accesslogno; then
     29 	echo "Accesslog overlay not available, test skipped"
     30 	exit 0
     31 fi
     32 
     33 MMR=2
     34 
     35 XDIR=$TESTDIR/srv
     36 TMP=$TESTDIR/tmp
     37 
     38 mkdir -p $TESTDIR
     39 cp -r $DATADIR/tls $TESTDIR
     40 
     41 $SLAPPASSWD -g -n >$CONFIGPWF
     42 
     43 if test x"$SYNCMODE" = x ; then
     44 	SYNCMODE=rp
     45 fi
     46 case "$SYNCMODE" in
     47 	ro)
     48 		SYNCTYPE="type=refreshOnly interval=00:00:00:03"
     49 		;;
     50 	rp)
     51 		SYNCTYPE="type=refreshAndPersist interval=00:00:00:03"
     52 		;;
     53 	*)
     54 		echo "unknown sync mode $SYNCMODE"
     55 		exit 1;
     56 		;;
     57 esac
     58 
     59 #
     60 # Test delta-sync mmr
     61 # - start servers
     62 # - configure over ldap
     63 # - populate over ldap
     64 # - configure syncrepl over ldap
     65 # - break replication
     66 # - modify each server separately
     67 # - restore replication
     68 # - compare results
     69 #
     70 
     71 nullExclude=""
     72 test $BACKEND = null && nullExclude="# "
     73 
     74 KILLPIDS=
     75 
     76 echo "Initializing server configurations..."
     77 n=1
     78 while [ $n -le $MMR ]; do
     79 
     80 DBDIR=${XDIR}$n/db
     81 CFDIR=${XDIR}$n/slapd.d
     82 
     83 mkdir -p ${XDIR}$n $DBDIR.1 $DBDIR.2 $CFDIR
     84 
     85 o=`expr 3 - $n`
     86 cat > $TMP <<EOF
     87 dn: cn=config
     88 objectClass: olcGlobal
     89 cn: config
     90 olcServerID: $n
     91 olcTLSCertificateFile: $TESTDIR/tls/certs/localhost.crt
     92 olcTLSCertificateKeyFile: $TESTDIR/tls/private/localhost.key
     93 
     94 EOF
     95 
     96 if [ "$SYNCPROV" = syncprovmod -o "$ACCESSLOG" = accesslogmod ]; then
     97   cat <<EOF >> $TMP
     98 dn: cn=module,cn=config
     99 objectClass: olcModuleList
    100 cn: module
    101 olcModulePath: $TESTWD/../servers/slapd/overlays
    102 EOF
    103   if [ "$SYNCPROV" = syncprovmod ]; then
    104   echo "olcModuleLoad: syncprov.la" >> $TMP
    105   fi
    106   if [ "$ACCESSLOG" = accesslogmod ]; then
    107   echo "olcModuleLoad: accesslog.la" >> $TMP
    108   fi
    109   echo "" >> $TMP
    110 fi
    111 
    112 if [ "$BACKENDTYPE" = mod ]; then
    113 cat <<EOF >> $TMP
    114 dn: cn=module,cn=config
    115 objectClass: olcModuleList
    116 cn: module
    117 olcModulePath: $TESTWD/../servers/slapd/back-$BACKEND
    118 olcModuleLoad: back_$BACKEND.la
    119 
    120 EOF
    121 fi
    122 MYURI=`eval echo '$URI'$n`
    123 PROVIDERURI=`eval echo '$URIP'$o`
    124 if test $INDEXDB = indexdb ; then
    125 INDEX1="olcDbIndex: objectClass,entryCSN,reqStart,reqDN,reqResult eq"
    126 INDEX2="olcDbIndex: objectClass,entryCSN,entryUUID eq"
    127 else
    128 INDEX1=
    129 INDEX2=
    130 fi
    131 cat >> $TMP <<EOF
    132 dn: cn=schema,cn=config
    133 objectclass: olcSchemaconfig
    134 cn: schema
    135 
    136 include: file://$ABS_SCHEMADIR/core.ldif
    137 
    138 include: file://$ABS_SCHEMADIR/cosine.ldif
    139 
    140 include: file://$ABS_SCHEMADIR/inetorgperson.ldif
    141 
    142 include: file://$ABS_SCHEMADIR/openldap.ldif
    143 
    144 include: file://$ABS_SCHEMADIR/nis.ldif
    145 
    146 dn: olcDatabase={0}config,cn=config
    147 objectClass: olcDatabaseConfig
    148 olcDatabase: {0}config
    149 olcRootPW:< file://$CONFIGPWF
    150 
    151 dn: olcDatabase={1}$BACKEND,cn=config
    152 objectClass: olcDatabaseConfig
    153 ${nullExclude}objectClass: olc${BACKEND}Config
    154 olcDatabase: {1}$BACKEND
    155 olcSuffix: cn=log
    156 ${nullExclude}olcDbDirectory: ${DBDIR}.1
    157 olcRootDN: $MANAGERDN
    158 $INDEX1
    159 
    160 dn: olcOverlay=syncprov,olcDatabase={1}$BACKEND,cn=config
    161 objectClass: olcOverlayConfig
    162 objectClass: olcSyncProvConfig
    163 olcOverlay: syncprov
    164 olcSpNoPresent: TRUE
    165 olcSpReloadHint: TRUE
    166 
    167 dn: olcDatabase={2}$BACKEND,cn=config
    168 objectClass: olcDatabaseConfig
    169 ${nullExclude}objectClass: olc${BACKEND}Config
    170 olcDatabase: {2}$BACKEND
    171 olcSuffix: $BASEDN
    172 ${nullExclude}olcDbDirectory: ${DBDIR}.2
    173 olcRootDN: $MANAGERDN
    174 olcRootPW: $PASSWD
    175 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple
    176   credentials=$PASSWD searchbase="$BASEDN" $SYNCTYPE
    177   retry="3 +" timeout=3 logbase="cn=log"
    178   logfilter="(&(objectclass=auditWriteObject)(reqresult=0))"
    179   syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt
    180   starttls=critical
    181 olcMultiProvider: TRUE
    182 $INDEX2
    183 
    184 dn: olcOverlay=syncprov,olcDatabase={2}$BACKEND,cn=config
    185 objectClass: olcOverlayConfig
    186 objectClass: olcSyncProvConfig
    187 olcOverlay: syncprov
    188 
    189 dn: olcOverlay=accesslog,olcDatabase={2}$BACKEND,cn=config
    190 objectClass: olcOverlayConfig
    191 objectClass: olcAccessLogConfig
    192 olcOverlay: accesslog
    193 olcAccessLogDB: cn=log
    194 olcAccessLogOps: writes
    195 olcAccessLogSuccess: TRUE
    196 
    197 EOF
    198 
    199 $SLAPADD -F $CFDIR -n 0  -d-1< $TMP > $TESTOUT 2>&1
    200 RC=$?
    201 if test $RC != 0 ; then
    202 	echo "slapadd failed ($RC)!"
    203 	exit $RC
    204 fi
    205 
    206 PORT=`eval echo '$PORT'$n`
    207 echo "Starting server $n on TCP/IP port $PORT..."
    208 cd ${XDIR}${n}
    209 LOG=`eval echo '$LOG'$n`
    210 $SLAPD -F slapd.d -h $MYURI -d $LVL > $LOG 2>&1 &
    211 PID=$!
    212 if test $WAIT != 0 ; then
    213     echo PID $PID
    214     read foo
    215 fi
    216 KILLPIDS="$PID $KILLPIDS"
    217 cd $TESTWD
    218 
    219 echo "Using ldapsearch to check that server $n is running..."
    220 for i in 0 1 2 3 4 5; do
    221 	$LDAPSEARCH -s base -b "" -H $MYURI \
    222 		'objectclass=*' > /dev/null 2>&1
    223 	RC=$?
    224 	if test $RC = 0 ; then
    225 		break
    226 	fi
    227 	echo "Waiting 5 seconds for slapd to start..."
    228 	sleep 5
    229 done
    230 
    231 if test $RC != 0 ; then
    232 	echo "ldapsearch failed ($RC)!"
    233 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    234 	exit $RC
    235 fi
    236 
    237 if [ $n = 1 ]; then
    238 echo "Using ldapadd for context on server 1..."
    239 $LDAPADD -D "$MANAGERDN" -H $URI1 -w $PASSWD -f $LDIFORDEREDCP \
    240 	>> $TESTOUT 2>&1
    241 RC=$?
    242 if test $RC != 0 ; then
    243 	echo "ldapadd failed for server $n database ($RC)!"
    244 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    245 	exit $RC
    246 fi
    247 fi
    248 
    249 n=`expr $n + 1`
    250 done
    251 
    252 echo "Using ldapadd to populate server 1..."
    253 $LDAPADD -D "$MANAGERDN" -H $URI1 -w $PASSWD -f $LDIFORDEREDNOCP \
    254 	>> $TESTOUT 2>&1
    255 RC=$?
    256 if test $RC != 0 ; then
    257 	echo "ldapadd failed for server $n database ($RC)!"
    258 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    259 	exit $RC
    260 fi
    261 
    262 echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..."
    263 sleep $SLEEP1
    264 
    265 n=1
    266 while [ $n -le $MMR ]; do
    267 PORT=`expr $BASEPORT + $n`
    268 URI="ldap://${LOCALHOST}:$PORT/"
    269 
    270 echo "Using ldapsearch to read all the entries from server $n..."
    271 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD  \
    272 	'objectclass=*' > $TESTDIR/server$n.out 2>&1
    273 RC=$?
    274 
    275 if test $RC != 0 ; then
    276 	echo "ldapsearch failed at server $n ($RC)!"
    277 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    278 	exit $RC
    279 fi
    280 $LDIFFILTER < $TESTDIR/server$n.out > $TESTDIR/server$n.flt
    281 n=`expr $n + 1`
    282 done
    283 
    284 n=2
    285 while [ $n -le $MMR ]; do
    286 echo "Comparing retrieved entries from server 1 and server $n..."
    287 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT
    288 
    289 if test $? != 0 ; then
    290 	echo "test failed - server 1 and server $n databases differ"
    291 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    292 	exit 1
    293 fi
    294 n=`expr $n + 1`
    295 done
    296 
    297 echo "Using ldapadd to populate server 2..."
    298 $LDAPADD -D "$MANAGERDN" -H $URI2 -w $PASSWD -f $LDIFADD1 \
    299 	>> $TESTOUT 2>&1
    300 RC=$?
    301 if test $RC != 0 ; then
    302 	echo "ldapadd failed for server 2 database ($RC)!"
    303 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    304 	exit $RC
    305 fi
    306 
    307 THEDN="cn=James A Jones 2,ou=Alumni Association,ou=People,dc=example,dc=com"
    308 sleep 1
    309 for i in 1 2 3; do
    310 	$LDAPSEARCH -S "" -b "$THEDN" -H $URI1 \
    311 		-s base '(objectClass=*)' entryCSN > "${PROVIDEROUT}.$i" 2>&1
    312 	RC=$?
    313 
    314 	if test $RC = 0 ; then
    315 		break
    316 	fi
    317 
    318 	if test $RC != 32 ; then
    319 		echo "ldapsearch failed at replica ($RC)!"
    320 		test $KILLSERVERS != no && kill -HUP $KILLPIDS
    321 		exit $RC
    322 	fi
    323 
    324 	echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..."
    325 	sleep $SLEEP1
    326 done
    327 
    328 n=1
    329 while [ $n -le $MMR ]; do
    330 PORT=`expr $BASEPORT + $n`
    331 URI="ldap://${LOCALHOST}:$PORT/"
    332 
    333 echo "Using ldapsearch to read all the entries from server $n..."
    334 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD  \
    335 	'objectclass=*' > $TESTDIR/server$n.out 2>&1
    336 RC=$?
    337 
    338 if test $RC != 0 ; then
    339 	echo "ldapsearch failed at server $n ($RC)!"
    340 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    341 	exit $RC
    342 fi
    343 $LDIFFILTER < $TESTDIR/server$n.out > $TESTDIR/server$n.flt
    344 n=`expr $n + 1`
    345 done
    346 
    347 n=2
    348 while [ $n -le $MMR ]; do
    349 echo "Comparing retrieved entries from server 1 and server $n..."
    350 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT
    351 
    352 if test $? != 0 ; then
    353 	echo "test failed - server 1 and server $n databases differ"
    354 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    355 	exit 1
    356 fi
    357 n=`expr $n + 1`
    358 done
    359 
    360 echo "Breaking replication between server 1 and 2..."
    361 n=1
    362 while [ $n -le $MMR ]; do
    363 o=`expr 3 - $n`
    364 MYURI=`eval echo '$URI'$n`
    365 PROVIDERURI=`eval echo '$URIP'$o`
    366 $LDAPMODIFY -D cn=config -H $MYURI -y $CONFIGPWF > $TESTOUT 2>&1 <<EOF
    367 dn: olcDatabase={2}$BACKEND,cn=config
    368 changetype: modify
    369 replace: olcSyncRepl
    370 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple
    371   credentials=InvalidPw searchbase="$BASEDN" $SYNCTYPE
    372   retry="3 +" timeout=3 logbase="cn=log"
    373   logfilter="(&(objectclass=auditWriteObject)(reqresult=0))"
    374   syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt
    375   starttls=critical
    376 -
    377 replace: olcMultiProvider
    378 olcMultiProvider: TRUE
    379 
    380 EOF
    381 RC=$?
    382 if test $RC != 0 ; then
    383 	echo "ldapmodify failed for server $n config ($RC)!"
    384 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    385 	exit $RC
    386 fi
    387 n=`expr $n + 1`
    388 done
    389 
    390 echo "Using ldapmodify to force conflicts between server 1 and 2..."
    391 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \
    392 	>> $TESTOUT 2>&1 << EOF
    393 dn: $THEDN
    394 changetype: modify
    395 add: description
    396 description: Amazing
    397 
    398 EOF
    399 RC=$?
    400 if test $RC != 0 ; then
    401 	echo "ldapmodify failed for server 1 database ($RC)!"
    402 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    403 	exit $RC
    404 fi
    405 
    406 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \
    407 	>> $TESTOUT 2>&1 << EOF
    408 dn: $THEDN
    409 changetype: modify
    410 add: description
    411 description: Stupendous
    412 
    413 EOF
    414 RC=$?
    415 if test $RC != 0 ; then
    416 	echo "ldapmodify failed for server 2 database ($RC)!"
    417 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    418 	exit $RC
    419 fi
    420 
    421 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \
    422 	>> $TESTOUT 2>&1 << EOF
    423 dn: $THEDN
    424 changetype: modify
    425 delete: description
    426 description: Outstanding
    427 -
    428 add: description
    429 description: Mindboggling
    430 
    431 EOF
    432 RC=$?
    433 if test $RC != 0 ; then
    434 	echo "ldapmodify failed for server 1 database ($RC)!"
    435 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    436 	exit $RC
    437 fi
    438 
    439 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \
    440 	>> $TESTOUT 2>&1 << EOF
    441 dn: $THEDN
    442 changetype: modify
    443 delete: description
    444 description: OutStanding
    445 -
    446 add: description
    447 description: Bizarre
    448 
    449 EOF
    450 RC=$?
    451 if test $RC != 0 ; then
    452 	echo "ldapmodify failed for server 2 database ($RC)!"
    453 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    454 	exit $RC
    455 fi
    456 
    457 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \
    458 	>> $TESTOUT 2>&1 << EOF
    459 dn: $THEDN
    460 changetype: modify
    461 add: carLicense
    462 carLicense: 123-XYZ
    463 -
    464 add: employeeNumber
    465 employeeNumber: 32
    466 
    467 EOF
    468 RC=$?
    469 if test $RC != 0 ; then
    470 	echo "ldapmodify failed for server 1 database ($RC)!"
    471 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    472 	exit $RC
    473 fi
    474 
    475 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \
    476 	>> $TESTOUT 2>&1 << EOF
    477 dn: $THEDN
    478 changetype: modify
    479 add: employeeType
    480 employeeType: deadwood
    481 -
    482 add: employeeNumber
    483 employeeNumber: 64
    484 
    485 EOF
    486 RC=$?
    487 if test $RC != 0 ; then
    488 	echo "ldapmodify failed for server 2 database ($RC)!"
    489 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    490 	exit $RC
    491 fi
    492 
    493 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \
    494 	>> $TESTOUT 2>&1 << EOF
    495 dn: $THEDN
    496 changetype: modify
    497 replace: sn
    498 sn: Replaced later
    499 -
    500 replace: sn
    501 sn: Surname
    502 EOF
    503 RC=$?
    504 if test $RC != 0 ; then
    505 	echo "ldapmodify failed for server 1 database ($RC)!"
    506 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    507 	exit $RC
    508 fi
    509 
    510 echo "Restoring replication between server 1 and 2..."
    511 n=1
    512 while [ $n -le $MMR ]; do
    513 o=`expr 3 - $n`
    514 MYURI=`eval echo '$URI'$n`
    515 PROVIDERURI=`eval echo '$URIP'$o`
    516 $LDAPMODIFY -D cn=config -H $MYURI -y $CONFIGPWF > $TESTOUT 2>&1 <<EOF
    517 dn: olcDatabase={2}$BACKEND,cn=config
    518 changetype: modify
    519 replace: olcSyncRepl
    520 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple
    521   credentials=$PASSWD searchbase="$BASEDN" $SYNCTYPE
    522   retry="3 +" timeout=3 logbase="cn=log"
    523   logfilter="(&(objectclass=auditWriteObject)(reqresult=0))"
    524   syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt
    525   starttls=critical
    526 -
    527 replace: olcMultiProvider
    528 olcMultiProvider: TRUE
    529 
    530 EOF
    531 RC=$?
    532 if test $RC != 0 ; then
    533 	echo "ldapmodify failed for server $n config ($RC)!"
    534 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    535 	exit $RC
    536 fi
    537 n=`expr $n + 1`
    538 done
    539 
    540 echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..."
    541 sleep $SLEEP1
    542 
    543 n=1
    544 while [ $n -le $MMR ]; do
    545 PORT=`expr $BASEPORT + $n`
    546 URI="ldap://${LOCALHOST}:$PORT/"
    547 
    548 echo "Using ldapsearch to read all the entries from server $n..."
    549 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD  \
    550 	'objectclass=*' > $TESTDIR/server$n.out 2>&1
    551 RC=$?
    552 
    553 if test $RC != 0 ; then
    554 	echo "ldapsearch failed at server $n ($RC)!"
    555 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    556 	exit $RC
    557 fi
    558 $LDIFFILTER -s a < $TESTDIR/server$n.out > $TESTDIR/server$n.flt
    559 n=`expr $n + 1`
    560 done
    561 
    562 n=2
    563 while [ $n -le $MMR ]; do
    564 echo "Comparing retrieved entries from server 1 and server $n..."
    565 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT
    566 
    567 if test $? != 0 ; then
    568 	echo "test failed - server 1 and server $n databases differ"
    569 	test $KILLSERVERS != no && kill -HUP $KILLPIDS
    570 	exit 1
    571 fi
    572 n=`expr $n + 1`
    573 done
    574 
    575 test $KILLSERVERS != no && kill -HUP $KILLPIDS
    576 
    577 echo ">>>>> Test succeeded"
    578 
    579 test $KILLSERVERS != no && wait
    580 
    581 exit 0
    582