1 #! /bin/sh 2 # $OpenLDAP$ 3 ## This work is part of OpenLDAP Software <http://www.openldap.org/>. 4 ## 5 ## Copyright 1998-2024 The OpenLDAP Foundation. 6 ## All rights reserved. 7 ## 8 ## Redistribution and use in source and binary forms, with or without 9 ## modification, are permitted only as authorized by the OpenLDAP 10 ## Public License. 11 ## 12 ## A copy of this license is available in the file LICENSE in the 13 ## top-level directory of the distribution or, alternatively, at 14 ## <http://www.OpenLDAP.org/license.html>. 15 16 echo "running defines.sh" 17 . $SRCDIR/scripts/defines.sh 18 19 if test $WITH_TLS = no ; then 20 echo "TLS support not available, test skipped" 21 exit 0 22 fi 23 24 if test $SYNCPROV = syncprovno; then 25 echo "Syncrepl provider overlay not available, test skipped" 26 exit 0 27 fi 28 if test $ACCESSLOG = accesslogno; then 29 echo "Accesslog overlay not available, test skipped" 30 exit 0 31 fi 32 33 MMR=2 34 35 XDIR=$TESTDIR/srv 36 TMP=$TESTDIR/tmp 37 38 mkdir -p $TESTDIR 39 cp -r $DATADIR/tls $TESTDIR 40 41 $SLAPPASSWD -g -n >$CONFIGPWF 42 43 if test x"$SYNCMODE" = x ; then 44 SYNCMODE=rp 45 fi 46 case "$SYNCMODE" in 47 ro) 48 SYNCTYPE="type=refreshOnly interval=00:00:00:03" 49 ;; 50 rp) 51 SYNCTYPE="type=refreshAndPersist interval=00:00:00:03" 52 ;; 53 *) 54 echo "unknown sync mode $SYNCMODE" 55 exit 1; 56 ;; 57 esac 58 59 # 60 # Test delta-sync mmr 61 # - start servers 62 # - configure over ldap 63 # - populate over ldap 64 # - configure syncrepl over ldap 65 # - break replication 66 # - modify each server separately 67 # - restore replication 68 # - compare results 69 # 70 71 nullExclude="" 72 test $BACKEND = null && nullExclude="# " 73 74 KILLPIDS= 75 76 echo "Initializing server configurations..." 77 n=1 78 while [ $n -le $MMR ]; do 79 80 DBDIR=${XDIR}$n/db 81 CFDIR=${XDIR}$n/slapd.d 82 83 mkdir -p ${XDIR}$n $DBDIR.1 $DBDIR.2 $CFDIR 84 85 o=`expr 3 - $n` 86 cat > $TMP <<EOF 87 dn: cn=config 88 objectClass: olcGlobal 89 cn: config 90 olcServerID: $n 91 olcTLSCertificateFile: $TESTDIR/tls/certs/localhost.crt 92 olcTLSCertificateKeyFile: $TESTDIR/tls/private/localhost.key 93 94 EOF 95 96 if [ "$SYNCPROV" = syncprovmod -o "$ACCESSLOG" = accesslogmod ]; then 97 cat <<EOF >> $TMP 98 dn: cn=module,cn=config 99 objectClass: olcModuleList 100 cn: module 101 olcModulePath: $TESTWD/../servers/slapd/overlays 102 EOF 103 if [ "$SYNCPROV" = syncprovmod ]; then 104 echo "olcModuleLoad: syncprov.la" >> $TMP 105 fi 106 if [ "$ACCESSLOG" = accesslogmod ]; then 107 echo "olcModuleLoad: accesslog.la" >> $TMP 108 fi 109 echo "" >> $TMP 110 fi 111 112 if [ "$BACKENDTYPE" = mod ]; then 113 cat <<EOF >> $TMP 114 dn: cn=module,cn=config 115 objectClass: olcModuleList 116 cn: module 117 olcModulePath: $TESTWD/../servers/slapd/back-$BACKEND 118 olcModuleLoad: back_$BACKEND.la 119 120 EOF 121 fi 122 MYURI=`eval echo '$URI'$n` 123 PROVIDERURI=`eval echo '$URIP'$o` 124 if test $INDEXDB = indexdb ; then 125 INDEX1="olcDbIndex: objectClass,entryCSN,reqStart,reqDN,reqResult eq" 126 INDEX2="olcDbIndex: objectClass,entryCSN,entryUUID eq" 127 else 128 INDEX1= 129 INDEX2= 130 fi 131 cat >> $TMP <<EOF 132 dn: cn=schema,cn=config 133 objectclass: olcSchemaconfig 134 cn: schema 135 136 include: file://$ABS_SCHEMADIR/core.ldif 137 138 include: file://$ABS_SCHEMADIR/cosine.ldif 139 140 include: file://$ABS_SCHEMADIR/inetorgperson.ldif 141 142 include: file://$ABS_SCHEMADIR/openldap.ldif 143 144 include: file://$ABS_SCHEMADIR/nis.ldif 145 146 dn: olcDatabase={0}config,cn=config 147 objectClass: olcDatabaseConfig 148 olcDatabase: {0}config 149 olcRootPW:< file://$CONFIGPWF 150 151 dn: olcDatabase={1}$BACKEND,cn=config 152 objectClass: olcDatabaseConfig 153 ${nullExclude}objectClass: olc${BACKEND}Config 154 olcDatabase: {1}$BACKEND 155 olcSuffix: cn=log 156 ${nullExclude}olcDbDirectory: ${DBDIR}.1 157 olcRootDN: $MANAGERDN 158 $INDEX1 159 160 dn: olcOverlay=syncprov,olcDatabase={1}$BACKEND,cn=config 161 objectClass: olcOverlayConfig 162 objectClass: olcSyncProvConfig 163 olcOverlay: syncprov 164 olcSpNoPresent: TRUE 165 olcSpReloadHint: TRUE 166 167 dn: olcDatabase={2}$BACKEND,cn=config 168 objectClass: olcDatabaseConfig 169 ${nullExclude}objectClass: olc${BACKEND}Config 170 olcDatabase: {2}$BACKEND 171 olcSuffix: $BASEDN 172 ${nullExclude}olcDbDirectory: ${DBDIR}.2 173 olcRootDN: $MANAGERDN 174 olcRootPW: $PASSWD 175 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple 176 credentials=$PASSWD searchbase="$BASEDN" $SYNCTYPE 177 retry="3 +" timeout=3 logbase="cn=log" 178 logfilter="(&(objectclass=auditWriteObject)(reqresult=0))" 179 syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt 180 starttls=critical 181 olcMultiProvider: TRUE 182 $INDEX2 183 184 dn: olcOverlay=syncprov,olcDatabase={2}$BACKEND,cn=config 185 objectClass: olcOverlayConfig 186 objectClass: olcSyncProvConfig 187 olcOverlay: syncprov 188 189 dn: olcOverlay=accesslog,olcDatabase={2}$BACKEND,cn=config 190 objectClass: olcOverlayConfig 191 objectClass: olcAccessLogConfig 192 olcOverlay: accesslog 193 olcAccessLogDB: cn=log 194 olcAccessLogOps: writes 195 olcAccessLogSuccess: TRUE 196 197 EOF 198 199 $SLAPADD -F $CFDIR -n 0 -d-1< $TMP > $TESTOUT 2>&1 200 RC=$? 201 if test $RC != 0 ; then 202 echo "slapadd failed ($RC)!" 203 exit $RC 204 fi 205 206 PORT=`eval echo '$PORT'$n` 207 echo "Starting server $n on TCP/IP port $PORT..." 208 cd ${XDIR}${n} 209 LOG=`eval echo '$LOG'$n` 210 $SLAPD -F slapd.d -h $MYURI -d $LVL > $LOG 2>&1 & 211 PID=$! 212 if test $WAIT != 0 ; then 213 echo PID $PID 214 read foo 215 fi 216 KILLPIDS="$PID $KILLPIDS" 217 cd $TESTWD 218 219 echo "Using ldapsearch to check that server $n is running..." 220 for i in 0 1 2 3 4 5; do 221 $LDAPSEARCH -s base -b "" -H $MYURI \ 222 'objectclass=*' > /dev/null 2>&1 223 RC=$? 224 if test $RC = 0 ; then 225 break 226 fi 227 echo "Waiting 5 seconds for slapd to start..." 228 sleep 5 229 done 230 231 if test $RC != 0 ; then 232 echo "ldapsearch failed ($RC)!" 233 test $KILLSERVERS != no && kill -HUP $KILLPIDS 234 exit $RC 235 fi 236 237 if [ $n = 1 ]; then 238 echo "Using ldapadd for context on server 1..." 239 $LDAPADD -D "$MANAGERDN" -H $URI1 -w $PASSWD -f $LDIFORDEREDCP \ 240 >> $TESTOUT 2>&1 241 RC=$? 242 if test $RC != 0 ; then 243 echo "ldapadd failed for server $n database ($RC)!" 244 test $KILLSERVERS != no && kill -HUP $KILLPIDS 245 exit $RC 246 fi 247 fi 248 249 n=`expr $n + 1` 250 done 251 252 echo "Using ldapadd to populate server 1..." 253 $LDAPADD -D "$MANAGERDN" -H $URI1 -w $PASSWD -f $LDIFORDEREDNOCP \ 254 >> $TESTOUT 2>&1 255 RC=$? 256 if test $RC != 0 ; then 257 echo "ldapadd failed for server $n database ($RC)!" 258 test $KILLSERVERS != no && kill -HUP $KILLPIDS 259 exit $RC 260 fi 261 262 echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..." 263 sleep $SLEEP1 264 265 n=1 266 while [ $n -le $MMR ]; do 267 PORT=`expr $BASEPORT + $n` 268 URI="ldap://${LOCALHOST}:$PORT/" 269 270 echo "Using ldapsearch to read all the entries from server $n..." 271 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD \ 272 'objectclass=*' > $TESTDIR/server$n.out 2>&1 273 RC=$? 274 275 if test $RC != 0 ; then 276 echo "ldapsearch failed at server $n ($RC)!" 277 test $KILLSERVERS != no && kill -HUP $KILLPIDS 278 exit $RC 279 fi 280 $LDIFFILTER < $TESTDIR/server$n.out > $TESTDIR/server$n.flt 281 n=`expr $n + 1` 282 done 283 284 n=2 285 while [ $n -le $MMR ]; do 286 echo "Comparing retrieved entries from server 1 and server $n..." 287 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT 288 289 if test $? != 0 ; then 290 echo "test failed - server 1 and server $n databases differ" 291 test $KILLSERVERS != no && kill -HUP $KILLPIDS 292 exit 1 293 fi 294 n=`expr $n + 1` 295 done 296 297 echo "Using ldapadd to populate server 2..." 298 $LDAPADD -D "$MANAGERDN" -H $URI2 -w $PASSWD -f $LDIFADD1 \ 299 >> $TESTOUT 2>&1 300 RC=$? 301 if test $RC != 0 ; then 302 echo "ldapadd failed for server 2 database ($RC)!" 303 test $KILLSERVERS != no && kill -HUP $KILLPIDS 304 exit $RC 305 fi 306 307 THEDN="cn=James A Jones 2,ou=Alumni Association,ou=People,dc=example,dc=com" 308 sleep 1 309 for i in 1 2 3; do 310 $LDAPSEARCH -S "" -b "$THEDN" -H $URI1 \ 311 -s base '(objectClass=*)' entryCSN > "${PROVIDEROUT}.$i" 2>&1 312 RC=$? 313 314 if test $RC = 0 ; then 315 break 316 fi 317 318 if test $RC != 32 ; then 319 echo "ldapsearch failed at replica ($RC)!" 320 test $KILLSERVERS != no && kill -HUP $KILLPIDS 321 exit $RC 322 fi 323 324 echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..." 325 sleep $SLEEP1 326 done 327 328 n=1 329 while [ $n -le $MMR ]; do 330 PORT=`expr $BASEPORT + $n` 331 URI="ldap://${LOCALHOST}:$PORT/" 332 333 echo "Using ldapsearch to read all the entries from server $n..." 334 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD \ 335 'objectclass=*' > $TESTDIR/server$n.out 2>&1 336 RC=$? 337 338 if test $RC != 0 ; then 339 echo "ldapsearch failed at server $n ($RC)!" 340 test $KILLSERVERS != no && kill -HUP $KILLPIDS 341 exit $RC 342 fi 343 $LDIFFILTER < $TESTDIR/server$n.out > $TESTDIR/server$n.flt 344 n=`expr $n + 1` 345 done 346 347 n=2 348 while [ $n -le $MMR ]; do 349 echo "Comparing retrieved entries from server 1 and server $n..." 350 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT 351 352 if test $? != 0 ; then 353 echo "test failed - server 1 and server $n databases differ" 354 test $KILLSERVERS != no && kill -HUP $KILLPIDS 355 exit 1 356 fi 357 n=`expr $n + 1` 358 done 359 360 echo "Breaking replication between server 1 and 2..." 361 n=1 362 while [ $n -le $MMR ]; do 363 o=`expr 3 - $n` 364 MYURI=`eval echo '$URI'$n` 365 PROVIDERURI=`eval echo '$URIP'$o` 366 $LDAPMODIFY -D cn=config -H $MYURI -y $CONFIGPWF > $TESTOUT 2>&1 <<EOF 367 dn: olcDatabase={2}$BACKEND,cn=config 368 changetype: modify 369 replace: olcSyncRepl 370 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple 371 credentials=InvalidPw searchbase="$BASEDN" $SYNCTYPE 372 retry="3 +" timeout=3 logbase="cn=log" 373 logfilter="(&(objectclass=auditWriteObject)(reqresult=0))" 374 syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt 375 starttls=critical 376 - 377 replace: olcMultiProvider 378 olcMultiProvider: TRUE 379 380 EOF 381 RC=$? 382 if test $RC != 0 ; then 383 echo "ldapmodify failed for server $n config ($RC)!" 384 test $KILLSERVERS != no && kill -HUP $KILLPIDS 385 exit $RC 386 fi 387 n=`expr $n + 1` 388 done 389 390 echo "Using ldapmodify to force conflicts between server 1 and 2..." 391 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \ 392 >> $TESTOUT 2>&1 << EOF 393 dn: $THEDN 394 changetype: modify 395 add: description 396 description: Amazing 397 398 EOF 399 RC=$? 400 if test $RC != 0 ; then 401 echo "ldapmodify failed for server 1 database ($RC)!" 402 test $KILLSERVERS != no && kill -HUP $KILLPIDS 403 exit $RC 404 fi 405 406 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \ 407 >> $TESTOUT 2>&1 << EOF 408 dn: $THEDN 409 changetype: modify 410 add: description 411 description: Stupendous 412 413 EOF 414 RC=$? 415 if test $RC != 0 ; then 416 echo "ldapmodify failed for server 2 database ($RC)!" 417 test $KILLSERVERS != no && kill -HUP $KILLPIDS 418 exit $RC 419 fi 420 421 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \ 422 >> $TESTOUT 2>&1 << EOF 423 dn: $THEDN 424 changetype: modify 425 delete: description 426 description: Outstanding 427 - 428 add: description 429 description: Mindboggling 430 431 EOF 432 RC=$? 433 if test $RC != 0 ; then 434 echo "ldapmodify failed for server 1 database ($RC)!" 435 test $KILLSERVERS != no && kill -HUP $KILLPIDS 436 exit $RC 437 fi 438 439 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \ 440 >> $TESTOUT 2>&1 << EOF 441 dn: $THEDN 442 changetype: modify 443 delete: description 444 description: OutStanding 445 - 446 add: description 447 description: Bizarre 448 449 EOF 450 RC=$? 451 if test $RC != 0 ; then 452 echo "ldapmodify failed for server 2 database ($RC)!" 453 test $KILLSERVERS != no && kill -HUP $KILLPIDS 454 exit $RC 455 fi 456 457 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \ 458 >> $TESTOUT 2>&1 << EOF 459 dn: $THEDN 460 changetype: modify 461 add: carLicense 462 carLicense: 123-XYZ 463 - 464 add: employeeNumber 465 employeeNumber: 32 466 467 EOF 468 RC=$? 469 if test $RC != 0 ; then 470 echo "ldapmodify failed for server 1 database ($RC)!" 471 test $KILLSERVERS != no && kill -HUP $KILLPIDS 472 exit $RC 473 fi 474 475 $LDAPMODIFY -D "$MANAGERDN" -H $URI2 -w $PASSWD \ 476 >> $TESTOUT 2>&1 << EOF 477 dn: $THEDN 478 changetype: modify 479 add: employeeType 480 employeeType: deadwood 481 - 482 add: employeeNumber 483 employeeNumber: 64 484 485 EOF 486 RC=$? 487 if test $RC != 0 ; then 488 echo "ldapmodify failed for server 2 database ($RC)!" 489 test $KILLSERVERS != no && kill -HUP $KILLPIDS 490 exit $RC 491 fi 492 493 $LDAPMODIFY -D "$MANAGERDN" -H $URI1 -w $PASSWD \ 494 >> $TESTOUT 2>&1 << EOF 495 dn: $THEDN 496 changetype: modify 497 replace: sn 498 sn: Replaced later 499 - 500 replace: sn 501 sn: Surname 502 EOF 503 RC=$? 504 if test $RC != 0 ; then 505 echo "ldapmodify failed for server 1 database ($RC)!" 506 test $KILLSERVERS != no && kill -HUP $KILLPIDS 507 exit $RC 508 fi 509 510 echo "Restoring replication between server 1 and 2..." 511 n=1 512 while [ $n -le $MMR ]; do 513 o=`expr 3 - $n` 514 MYURI=`eval echo '$URI'$n` 515 PROVIDERURI=`eval echo '$URIP'$o` 516 $LDAPMODIFY -D cn=config -H $MYURI -y $CONFIGPWF > $TESTOUT 2>&1 <<EOF 517 dn: olcDatabase={2}$BACKEND,cn=config 518 changetype: modify 519 replace: olcSyncRepl 520 olcSyncRepl: rid=001 provider=$PROVIDERURI binddn="$MANAGERDN" bindmethod=simple 521 credentials=$PASSWD searchbase="$BASEDN" $SYNCTYPE 522 retry="3 +" timeout=3 logbase="cn=log" 523 logfilter="(&(objectclass=auditWriteObject)(reqresult=0))" 524 syncdata=accesslog tls_cacert=$TESTDIR/tls/ca/certs/testsuiteCA.crt 525 starttls=critical 526 - 527 replace: olcMultiProvider 528 olcMultiProvider: TRUE 529 530 EOF 531 RC=$? 532 if test $RC != 0 ; then 533 echo "ldapmodify failed for server $n config ($RC)!" 534 test $KILLSERVERS != no && kill -HUP $KILLPIDS 535 exit $RC 536 fi 537 n=`expr $n + 1` 538 done 539 540 echo "Waiting $SLEEP1 seconds for syncrepl to receive changes..." 541 sleep $SLEEP1 542 543 n=1 544 while [ $n -le $MMR ]; do 545 PORT=`expr $BASEPORT + $n` 546 URI="ldap://${LOCALHOST}:$PORT/" 547 548 echo "Using ldapsearch to read all the entries from server $n..." 549 $LDAPSEARCH -S "" -b "$BASEDN" -D "$MANAGERDN" -H $URI -w $PASSWD \ 550 'objectclass=*' > $TESTDIR/server$n.out 2>&1 551 RC=$? 552 553 if test $RC != 0 ; then 554 echo "ldapsearch failed at server $n ($RC)!" 555 test $KILLSERVERS != no && kill -HUP $KILLPIDS 556 exit $RC 557 fi 558 $LDIFFILTER -s a < $TESTDIR/server$n.out > $TESTDIR/server$n.flt 559 n=`expr $n + 1` 560 done 561 562 n=2 563 while [ $n -le $MMR ]; do 564 echo "Comparing retrieved entries from server 1 and server $n..." 565 $CMP $PROVIDERFLT $TESTDIR/server$n.flt > $CMPOUT 566 567 if test $? != 0 ; then 568 echo "test failed - server 1 and server $n databases differ" 569 test $KILLSERVERS != no && kill -HUP $KILLPIDS 570 exit 1 571 fi 572 n=`expr $n + 1` 573 done 574 575 test $KILLSERVERS != no && kill -HUP $KILLPIDS 576 577 echo ">>>>> Test succeeded" 578 579 test $KILLSERVERS != no && wait 580 581 exit 0 582