-def set_nameserver(t, nameserver):
- '''set the nameserver in resolv.conf'''
- t.write_file("/etc/resolv.conf.wintest", '''
-# Generated by wintest, the Samba v Windows automated testing system
-nameserver %s
-
-# your original resolv.conf appears below:
-''' % t.substitute(nameserver))
- child = t.pexpect_spawn("cat /etc/resolv.conf", crlf=False)
- i = child.expect(['your original resolv.conf appears below:', pexpect.EOF])
- if i == 0:
- child.expect(pexpect.EOF)
- contents = child.before.lstrip().replace('\r', '')
- t.write_file('/etc/resolv.conf.wintest', contents, mode='a')
- t.write_file('/etc/resolv.conf.wintest-bak', contents)
- t.run_cmd("mv -f /etc/resolv.conf.wintest /etc/resolv.conf")
- t.resolv_conf_backup = '/etc/resolv.conf.wintest-bak';
-
-
-def restore_resolv_conf(t):
- '''restore the /etc/resolv.conf after testing is complete'''
- if getattr(t, 'resolv_conf_backup', False):
- t.info("restoring /etc/resolv.conf")
- t.run_cmd("mv -f %s /etc/resolv.conf" % t.resolv_conf_backup)
-
-
-def rndc_cmd(t, cmd, checkfail=True):
- '''run a rndc command'''
- t.run_cmd("${RNDC} -c ${PREFIX}/etc/rndc.conf %s" % cmd, checkfail=checkfail)
-
-def named_supports_gssapi_keytab(t):
- '''see if named supports tkey-gssapi-keytab'''
- t.write_file("${PREFIX}/named.conf.test",
- 'options { tkey-gssapi-keytab "test"; };')
- try:
- t.run_cmd("${NAMED_CHECKCONF} ${PREFIX}/named.conf.test")
- except subprocess.CalledProcessError:
- return False
- return True
-
-
-def configure_bind(t):
- t.chdir('${PREFIX}')
-
- nameserver = t.get_nameserver()
- if nameserver == t.getvar('INTERFACE_IP'):
- raise RuntimeError("old /etc/resolv.conf must not contain %s as a nameserver, this will create loops with the generated dns configuration" % nameserver)
- t.setvar('DNSSERVER', nameserver)
-
- if t.getvar('INTERFACE_IPV6'):
- ipv6_listen = 'listen-on-v6 port 53 { ${INTERFACE_IPV6}; };'
- else:
- ipv6_listen = ''
- t.setvar('BIND_LISTEN_IPV6', ipv6_listen)
-
- if named_supports_gssapi_keytab(t):
- t.setvar("NAMED_TKEY_OPTION",
- 'tkey-gssapi-keytab "${PREFIX}/private/dns.keytab";')
- else:
- t.info("LCREALM=${LCREALM}")
- t.setvar("NAMED_TKEY_OPTION",
- '''tkey-gssapi-credential "DNS/${LCREALM}";
- tkey-domain "${LCREALM}";
- ''')
- t.putenv("KRB5_CONFIG", '${PREFIX}/private/krb5.conf')
- t.putenv('KEYTAB_FILE', '${PREFIX}/private/dns.keytab')
- t.putenv('KRB5_KTNAME', '${PREFIX}/private/dns.keytab')
-
- t.write_file("etc/named.conf", '''
-options {
- listen-on port 53 { ${INTERFACE_IP}; };
- ${BIND_LISTEN_IPV6}
- directory "${PREFIX}/var/named";
- dump-file "${PREFIX}/var/named/data/cache_dump.db";
- pid-file "${PREFIX}/var/named/named.pid";
- statistics-file "${PREFIX}/var/named/data/named_stats.txt";
- memstatistics-file "${PREFIX}/var/named/data/named_mem_stats.txt";
- allow-query { any; };
- recursion yes;
- ${NAMED_TKEY_OPTION}
- max-cache-ttl 10;
- max-ncache-ttl 10;
-
- forward only;
- forwarders {
- ${DNSSERVER};
- };
-
-};
-
-key "rndc-key" {
- algorithm hmac-md5;
- secret "lA/cTrno03mt5Ju17ybEYw==";
-};
-
-controls {
- inet ${INTERFACE_IP} port 953
- allow { any; } keys { "rndc-key"; };
-};
-
-include "${PREFIX}/private/named.conf";
-''')
-
- # add forwarding for the windows domains
- domains = t.get_domains()
- for d in domains:
- t.write_file('etc/named.conf',
- '''
-zone "%s" IN {
- type forward;
- forward only;
- forwarders {
- %s;
- };
-};
-''' % (d, domains[d]),
- mode='a')
-
-
- t.write_file("etc/rndc.conf", '''
-# Start of rndc.conf
-key "rndc-key" {
- algorithm hmac-md5;
- secret "lA/cTrno03mt5Ju17ybEYw==";
-};
-
-options {
- default-key "rndc-key";
- default-server ${INTERFACE_IP};
- default-port 953;
-};
-''')
-
- set_nameserver(t, t.getvar('INTERFACE_IP'))
-
-
-def stop_bind(t):
- '''Stop our private BIND from listening and operating'''
- rndc_cmd(t, "stop", checkfail=False)
- t.port_wait("${INTERFACE_IP}", 53, wait_for_fail=True)
-
- t.run_cmd("rm -rf var/named")
-
-
-def start_bind(t):
- '''restart the test environment version of bind'''
- t.info("Restarting bind9")
- t.chdir('${PREFIX}')
-
- set_nameserver(t, t.getvar('INTERFACE_IP'))
-
- t.run_cmd("mkdir -p var/named/data")
- t.run_cmd("chown -R ${BIND_USER} var/named")
-
- t.bind_child = t.run_child("${BIND9} -u ${BIND_USER} -n 1 -c ${PREFIX}/etc/named.conf -g")
-
- t.port_wait("${INTERFACE_IP}", 53)
- rndc_cmd(t, "flush")
-
-def restart_bind(t):
- configure_bind(t)
- stop_bind(t)
- start_bind(t)
-