blob: b8d61e359a9bf8c67ea00d542abd2cebc1a2fc5d [file] [log] [blame]
raviteja-b8cc44052019-02-27 23:29:36 -06001#include "mock_user_mgr.hpp"
Nan Zhoue47c09d2022-10-25 00:06:41 +00002#include "user_mgr.hpp"
Patrick Williams9638afb2021-02-22 17:16:24 -06003
Ravi Teja417c0892020-08-22 08:04:01 -05004#include <sdbusplus/test/sdbus_mock.hpp>
Patrick Williams9638afb2021-02-22 17:16:24 -06005#include <xyz/openbmc_project/Common/error.hpp>
6#include <xyz/openbmc_project/User/Common/error.hpp>
7
8#include <exception>
Nan Zhoue48085d2022-10-25 00:07:04 +00009#include <filesystem>
10#include <fstream>
Patrick Williams9638afb2021-02-22 17:16:24 -060011
12#include <gtest/gtest.h>
raviteja-b8cc44052019-02-27 23:29:36 -060013
14namespace phosphor
15{
16namespace user
17{
18
19using ::testing::Return;
20
21using InternalFailure =
22 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure;
23
24class TestUserMgr : public testing::Test
25{
26 public:
Nan Zhou78d85042022-08-29 17:50:22 +000027 sdbusplus::SdBusMock sdBusMock;
Patrick Williamsb3ef4e12022-07-22 19:26:55 -050028 sdbusplus::bus_t bus;
raviteja-b8cc44052019-02-27 23:29:36 -060029 MockManager mockManager;
30
31 TestUserMgr() :
Nan Zhou78d85042022-08-29 17:50:22 +000032 bus(sdbusplus::get_mocked_new(&sdBusMock)), mockManager(bus, objpath)
Patrick Williams9638afb2021-02-22 17:16:24 -060033 {}
raviteja-b8cc44052019-02-27 23:29:36 -060034
Patrick Williams9638afb2021-02-22 17:16:24 -060035 void createLocalUser(const std::string& userName,
raviteja-b8cc44052019-02-27 23:29:36 -060036 std::vector<std::string> groupNames,
Patrick Williams9638afb2021-02-22 17:16:24 -060037 const std::string& priv, bool enabled)
raviteja-b8cc44052019-02-27 23:29:36 -060038 {
P Dheeraj Srujan Kumarb01e2fe2021-12-13 09:43:28 +053039 sdbusplus::message::object_path tempObjPath(usersObjPath);
40 tempObjPath /= userName;
41 std::string userObj(tempObjPath);
raviteja-b8cc44052019-02-27 23:29:36 -060042 mockManager.usersList.emplace(
Nan Zhou78d85042022-08-29 17:50:22 +000043 userName, std::make_unique<phosphor::user::Users>(
raviteja-b8cc44052019-02-27 23:29:36 -060044 mockManager.bus, userObj.c_str(), groupNames, priv,
Nan Zhou78d85042022-08-29 17:50:22 +000045 enabled, mockManager));
raviteja-b8cc44052019-02-27 23:29:36 -060046 }
47
48 DbusUserObj createPrivilegeMapperDbusObject(void)
49 {
50 DbusUserObj object;
51 DbusUserObjValue objValue;
Ravi Teja5fe724a2019-05-07 05:14:42 -050052
Nan Zhou78d85042022-08-29 17:50:22 +000053 DbusUserObjPath objPath("/xyz/openbmc_project/user/ldap/openldap");
Ravi Teja5fe724a2019-05-07 05:14:42 -050054 DbusUserPropVariant enabled(true);
55 DbusUserObjProperties property = {std::make_pair("Enabled", enabled)};
56 std::string intf = "xyz.openbmc_project.Object.Enable";
57 objValue.emplace(intf, property);
Nan Zhou78d85042022-08-29 17:50:22 +000058 object.emplace(objPath, objValue);
Ravi Teja5fe724a2019-05-07 05:14:42 -050059
Nan Zhou78d85042022-08-29 17:50:22 +000060 DbusUserObjPath objectPath(
Ravi Teja5fe724a2019-05-07 05:14:42 -050061 "/xyz/openbmc_project/user/ldap/openldap/role_map/1");
62 std::string group = "ldapGroup";
63 std::string priv = "priv-admin";
raviteja-b8cc44052019-02-27 23:29:36 -060064 DbusUserObjProperties properties = {std::make_pair("GroupName", group),
65 std::make_pair("Privilege", priv)};
66 std::string interface = "xyz.openbmc_project.User.PrivilegeMapperEntry";
67
68 objValue.emplace(interface, properties);
Nan Zhou78d85042022-08-29 17:50:22 +000069 object.emplace(objectPath, objValue);
raviteja-b8cc44052019-02-27 23:29:36 -060070
71 return object;
72 }
Ravi Teja5fe724a2019-05-07 05:14:42 -050073
74 DbusUserObj createLdapConfigObjectWithoutPrivilegeMapper(void)
75 {
76 DbusUserObj object;
77 DbusUserObjValue objValue;
78
Nan Zhou78d85042022-08-29 17:50:22 +000079 DbusUserObjPath objPath("/xyz/openbmc_project/user/ldap/openldap");
Ravi Teja5fe724a2019-05-07 05:14:42 -050080 DbusUserPropVariant enabled(true);
81 DbusUserObjProperties property = {std::make_pair("Enabled", enabled)};
82 std::string intf = "xyz.openbmc_project.Object.Enable";
83 objValue.emplace(intf, property);
Nan Zhou78d85042022-08-29 17:50:22 +000084 object.emplace(objPath, objValue);
Ravi Teja5fe724a2019-05-07 05:14:42 -050085 return object;
86 }
raviteja-b8cc44052019-02-27 23:29:36 -060087};
88
89TEST_F(TestUserMgr, ldapEntryDoesNotExist)
90{
91 std::string userName = "user";
92 UserInfoMap userInfo;
93
94 EXPECT_CALL(mockManager, getLdapGroupName(userName))
95 .WillRepeatedly(Return(""));
96 EXPECT_THROW(userInfo = mockManager.getUserInfo(userName), InternalFailure);
97}
98
99TEST_F(TestUserMgr, localUser)
100{
101 UserInfoMap userInfo;
102 std::string userName = "testUser";
103 std::string privilege = "priv-admin";
104 std::vector<std::string> groups{"testGroup"};
105 // Create local user
106 createLocalUser(userName, groups, privilege, true);
107 EXPECT_CALL(mockManager, userLockedForFailedAttempt(userName)).Times(1);
108 userInfo = mockManager.getUserInfo(userName);
109
110 EXPECT_EQ(privilege, std::get<std::string>(userInfo["UserPrivilege"]));
111 EXPECT_EQ(groups,
112 std::get<std::vector<std::string>>(userInfo["UserGroups"]));
113 EXPECT_EQ(true, std::get<bool>(userInfo["UserEnabled"]));
114 EXPECT_EQ(false, std::get<bool>(userInfo["UserLockedForFailedAttempt"]));
Joseph Reynolds3ab6cc22020-03-03 14:09:03 -0600115 EXPECT_EQ(false, std::get<bool>(userInfo["UserPasswordExpired"]));
raviteja-b8cc44052019-02-27 23:29:36 -0600116 EXPECT_EQ(false, std::get<bool>(userInfo["RemoteUser"]));
117}
118
119TEST_F(TestUserMgr, ldapUserWithPrivMapper)
120{
121 UserInfoMap userInfo;
122 std::string userName = "ldapUser";
123 std::string ldapGroup = "ldapGroup";
124
125 EXPECT_CALL(mockManager, getLdapGroupName(userName))
126 .WillRepeatedly(Return(ldapGroup));
127 // Create privilege mapper dbus object
128 DbusUserObj object = createPrivilegeMapperDbusObject();
129 EXPECT_CALL(mockManager, getPrivilegeMapperObject())
130 .WillRepeatedly(Return(object));
131 userInfo = mockManager.getUserInfo(userName);
132 EXPECT_EQ(true, std::get<bool>(userInfo["RemoteUser"]));
133 EXPECT_EQ("priv-admin", std::get<std::string>(userInfo["UserPrivilege"]));
134}
135
136TEST_F(TestUserMgr, ldapUserWithoutPrivMapper)
137{
138 UserInfoMap userInfo;
139 std::string userName = "ldapUser";
140 std::string ldapGroup = "ldapGroup";
raviteja-b8cc44052019-02-27 23:29:36 -0600141
142 EXPECT_CALL(mockManager, getLdapGroupName(userName))
143 .WillRepeatedly(Return(ldapGroup));
Ravi Teja5fe724a2019-05-07 05:14:42 -0500144 // Create LDAP config object without privilege mapper
145 DbusUserObj object = createLdapConfigObjectWithoutPrivilegeMapper();
raviteja-b8cc44052019-02-27 23:29:36 -0600146 EXPECT_CALL(mockManager, getPrivilegeMapperObject())
147 .WillRepeatedly(Return(object));
148 userInfo = mockManager.getUserInfo(userName);
149 EXPECT_EQ(true, std::get<bool>(userInfo["RemoteUser"]));
150 EXPECT_EQ("", std::get<std::string>(userInfo["UserPrivilege"]));
151}
Nan Zhoue47c09d2022-10-25 00:06:41 +0000152
153TEST(GetCSVFromVector, EmptyVectorReturnsEmptyString)
154{
155 EXPECT_EQ(getCSVFromVector({}), "");
156}
157
158TEST(GetCSVFromVector, ElementsAreJoinedByComma)
159{
160 EXPECT_EQ(getCSVFromVector(std::vector<std::string>{"123"}), "123");
161 EXPECT_EQ(getCSVFromVector(std::vector<std::string>{"123", "456"}),
162 "123,456");
163}
164
Nan Zhou332fb9d2022-10-25 00:07:03 +0000165TEST(RemoveStringFromCSV, WithoutDeleteStringReturnsFalse)
166{
167 std::string expected = "whatever,https";
168 std::string str = expected;
169 EXPECT_FALSE(removeStringFromCSV(str, "ssh"));
170 EXPECT_EQ(str, expected);
171
172 std::string empty;
173 EXPECT_FALSE(removeStringFromCSV(empty, "ssh"));
174}
175
176TEST(RemoveStringFromCSV, WithDeleteStringReturnsTrue)
177{
178 std::string expected = "whatever";
179 std::string str = "whatever,https";
180 EXPECT_TRUE(removeStringFromCSV(str, "https"));
181 EXPECT_EQ(str, expected);
182
183 str = "https";
184 EXPECT_TRUE(removeStringFromCSV(str, "https"));
185 EXPECT_EQ(str, "");
186}
187
Nan Zhoue48085d2022-10-25 00:07:04 +0000188namespace
189{
190inline constexpr const char* objectRootInTest = "/xyz/openbmc_project/user";
191
192// Fake config; referenced config on real BMC
193inline constexpr const char* rawConfig = R"(
194#
195# /etc/pam.d/common-password - password-related modules common to all services
196#
197# This file is included from other service-specific PAM config files,
198# and should contain a list of modules that define the services to be
199# used to change user passwords. The default is pam_unix.
200
201# Explanation of pam_unix options:
202#
203# The "sha512" option enables salted SHA512 passwords. Without this option,
204# the default is Unix crypt. Prior releases used the option "md5".
205#
206# The "obscure" option replaces the old `OBSCURE_CHECKS_ENAB' option in
207# login.defs.
208#
209# See the pam_unix manpage for other options.
210
211# here are the per-package modules (the "Primary" block)
212password [success=ok default=die] pam_tally2.so debug enforce_for_root reject_username minlen=8 difok=0 lcredit=0 ocredit=0 dcredit=0 ucredit=0 #some comments
213password [success=ok default=die] pam_cracklib.so debug enforce_for_root reject_username minlen=8 difok=0 lcredit=0 ocredit=0 dcredit=0 ucredit=0 #some comments
214password [success=ok default=die] pam_ipmicheck.so spec_grp_name=ipmi use_authtok
215password [success=ok ignore=ignore default=die] pam_pwhistory.so debug enforce_for_root remember=0 use_authtok
216password [success=ok default=die] pam_unix.so sha512 use_authtok
217password [success=1 default=die] pam_ipmisave.so spec_grp_name=ipmi spec_pass_file=/etc/ipmi_pass key_file=/etc/key_file
218# here's the fallback if no module succeeds
219password requisite pam_deny.so
220# prime the stack with a positive return value if there isn't one already;
221# this avoids us returning an error just because nothing sets a success code
222# since the modules above will each just jump around
223password required pam_permit.so
224# and here are more per-package modules (the "Additional" block)
225)";
226} // namespace
227
228void dumpStringToFile(const std::string& str, const std::string& filePath)
229{
230 std::ofstream outputFileStream;
231
232 outputFileStream.exceptions(std::ofstream::failbit | std::ofstream::badbit |
233 std::ofstream::eofbit);
234
235 outputFileStream.open(filePath, std::ios::out);
236 outputFileStream << str << "\n" << std::flush;
237 outputFileStream.close();
238}
239
240void removeFile(const std::string& filePath)
241{
242 std::filesystem::remove(filePath);
243}
244
245class UserMgrInTest : public testing::Test, public UserMgr
246{
247 public:
248 UserMgrInTest() : UserMgr(busInTest, objectRootInTest)
249 {
250 tempPamConfigFile = "/tmp/test-data-XXXXXX";
251 mktemp(tempPamConfigFile.data());
252 EXPECT_NO_THROW(dumpStringToFile(rawConfig, tempPamConfigFile));
253 // Set config files to test files
254 pamPasswdConfigFile = tempPamConfigFile;
255 pamAuthConfigFile = tempPamConfigFile;
Nan Zhou49c81362022-10-25 00:07:08 +0000256
257 ON_CALL(*this, executeUserAdd).WillByDefault(testing::Return());
258
259 ON_CALL(*this, executeUserDelete).WillByDefault(testing::Return());
260
261 ON_CALL(*this, getIpmiUsersCount).WillByDefault(testing::Return(0));
Nan Zhouf25443e2022-10-25 00:07:11 +0000262
263 ON_CALL(*this, executeUserRename).WillByDefault(testing::Return());
Nan Zhoufef63032022-10-25 00:07:12 +0000264
265 ON_CALL(*this, executeUserModify(testing::_, testing::_, testing::_))
266 .WillByDefault(testing::Return());
Nan Zhoue48085d2022-10-25 00:07:04 +0000267 }
268
269 ~UserMgrInTest() override
270 {
271 EXPECT_NO_THROW(removeFile(tempPamConfigFile));
272 }
273
Nan Zhou49c81362022-10-25 00:07:08 +0000274 MOCK_METHOD(void, executeUserAdd, (const char*, const char*, bool, bool),
275 (override));
276
277 MOCK_METHOD(void, executeUserDelete, (const char*), (override));
278
279 MOCK_METHOD(size_t, getIpmiUsersCount, (), (override));
280
Nan Zhouf25443e2022-10-25 00:07:11 +0000281 MOCK_METHOD(void, executeUserRename, (const char*, const char*),
282 (override));
283
Nan Zhoufef63032022-10-25 00:07:12 +0000284 MOCK_METHOD(void, executeUserModify, (const char*, const char*, bool),
285 (override));
286
287 protected:
Nan Zhoue48085d2022-10-25 00:07:04 +0000288 static sdbusplus::bus_t busInTest;
289 std::string tempPamConfigFile;
290};
291
292sdbusplus::bus_t UserMgrInTest::busInTest = sdbusplus::bus::new_default();
293
294TEST_F(UserMgrInTest, GetPamModuleArgValueOnSuccess)
295{
296 std::string minLen;
297 EXPECT_EQ(getPamModuleArgValue("pam_tally2.so", "minlen", minLen), 0);
298 EXPECT_EQ(minLen, "8");
299 EXPECT_EQ(getPamModuleArgValue("pam_cracklib.so", "minlen", minLen), 0);
300 EXPECT_EQ(minLen, "8");
301}
302
303TEST_F(UserMgrInTest, SetPamModuleArgValueOnSuccess)
304{
305 EXPECT_EQ(setPamModuleArgValue("pam_cracklib.so", "minlen", "16"), 0);
306 EXPECT_EQ(setPamModuleArgValue("pam_tally2.so", "minlen", "16"), 0);
307 std::string minLen;
308 EXPECT_EQ(getPamModuleArgValue("pam_tally2.so", "minlen", minLen), 0);
309 EXPECT_EQ(minLen, "16");
310 EXPECT_EQ(getPamModuleArgValue("pam_cracklib.so", "minlen", minLen), 0);
311 EXPECT_EQ(minLen, "16");
312}
313
314TEST_F(UserMgrInTest, GetPamModuleArgValueOnFailure)
315{
316 EXPECT_NO_THROW(dumpStringToFile("whatever", tempPamConfigFile));
317 std::string minLen;
318 EXPECT_EQ(getPamModuleArgValue("pam_tally2.so", "minlen", minLen), -1);
319 EXPECT_EQ(getPamModuleArgValue("pam_cracklib.so", "minlen", minLen), -1);
320
321 EXPECT_NO_THROW(removeFile(tempPamConfigFile));
322 EXPECT_EQ(getPamModuleArgValue("pam_tally2.so", "minlen", minLen), -1);
323 EXPECT_EQ(getPamModuleArgValue("pam_cracklib.so", "minlen", minLen), -1);
324}
325
326TEST_F(UserMgrInTest, SetPamModuleArgValueOnFailure)
327{
328 EXPECT_NO_THROW(dumpStringToFile("whatever", tempPamConfigFile));
329 EXPECT_EQ(setPamModuleArgValue("pam_cracklib.so", "minlen", "16"), -1);
330 EXPECT_EQ(setPamModuleArgValue("pam_tally2.so", "minlen", "16"), -1);
331
332 EXPECT_NO_THROW(removeFile(tempPamConfigFile));
333 EXPECT_EQ(setPamModuleArgValue("pam_cracklib.so", "minlen", "16"), -1);
334 EXPECT_EQ(setPamModuleArgValue("pam_tally2.so", "minlen", "16"), -1);
335}
336
Nan Zhou8a11d992022-10-25 00:07:06 +0000337TEST_F(UserMgrInTest, IsUserExistEmptyInputThrowsError)
338{
339 EXPECT_THROW(
340 isUserExist(""),
341 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
342}
343
344TEST_F(UserMgrInTest, ThrowForUserDoesNotExistThrowsError)
345{
346 EXPECT_THROW(throwForUserDoesNotExist("whatever"),
347 sdbusplus::xyz::openbmc_project::User::Common::Error::
348 UserNameDoesNotExist);
349}
350
351TEST_F(UserMgrInTest, ThrowForUserExistsThrowsError)
352{
353 EXPECT_THROW(
354 throwForUserExists("root"),
355 sdbusplus::xyz::openbmc_project::User::Common::Error::UserNameExists);
356}
357
Nan Zhou40e44972022-10-25 00:07:07 +0000358TEST_F(
359 UserMgrInTest,
360 ThrowForUserNameConstraintsExceedIpmiMaxUserNameLenThrowsUserNameGroupFail)
361{
362 std::string strWith17Chars(17, 'A');
363 EXPECT_THROW(throwForUserNameConstraints(strWith17Chars, {"ipmi"}),
364 sdbusplus::xyz::openbmc_project::User::Common::Error::
365 UserNameGroupFail);
366}
367
368TEST_F(
369 UserMgrInTest,
370 ThrowForUserNameConstraintsExceedSystemMaxUserNameLenThrowsInvalidArgument)
371{
372 std::string strWith31Chars(31, 'A');
373 EXPECT_THROW(
374 throwForUserNameConstraints(strWith31Chars, {}),
375 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
376}
377
378TEST_F(UserMgrInTest,
379 ThrowForUserNameConstraintsRegexMismatchThrowsInvalidArgument)
380{
381 std::string startWithNumber = "0ABC";
382 EXPECT_THROW(
383 throwForUserNameConstraints(startWithNumber, {"ipmi"}),
384 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
385}
386
Nan Zhou49c81362022-10-25 00:07:08 +0000387TEST_F(UserMgrInTest, UserAddNotRootFailedWithInternalFailure)
388{
389 EXPECT_THROW(
390 UserMgr::executeUserAdd("user0", "ipmi,ssh", true, true),
391 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
392}
393
394TEST_F(UserMgrInTest, UserDeleteNotRootFailedWithInternalFailure)
395{
396 EXPECT_THROW(
397 UserMgr::executeUserDelete("user0"),
398 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
399}
400
401TEST_F(UserMgrInTest,
402 ThrowForMaxGrpUserCountThrowsNoResourceWhenIpmiUserExceedLimit)
403{
404 EXPECT_CALL(*this, getIpmiUsersCount()).WillOnce(Return(ipmiMaxUsers));
405 EXPECT_THROW(
406 throwForMaxGrpUserCount({"ipmi"}),
407 sdbusplus::xyz::openbmc_project::User::Common::Error::NoResource);
408}
409
410TEST_F(UserMgrInTest, CreateUserThrowsInternalFailureWhenExecuteUserAddFails)
411{
412 EXPECT_CALL(*this, executeUserAdd)
413 .WillOnce(testing::Throw(
414 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure()));
415 EXPECT_THROW(
416 createUser("whatever", {"redfish"}, "", true),
417 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
418}
419
420TEST_F(UserMgrInTest, DeleteUserThrowsInternalFailureWhenExecuteUserDeleteFails)
421{
422 std::string username = "user";
423 EXPECT_NO_THROW(
424 UserMgr::createUser(username, {"redfish", "ssh"}, "priv-user", true));
425 EXPECT_CALL(*this, executeUserDelete(testing::StrEq(username)))
426 .WillOnce(testing::Throw(
427 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure()))
428 .WillOnce(testing::DoDefault());
429
430 EXPECT_THROW(
431 deleteUser(username),
432 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
433 EXPECT_NO_THROW(UserMgr::deleteUser(username));
434}
435
Nan Zhou589aeb42022-10-25 00:07:09 +0000436TEST_F(UserMgrInTest, ThrowForInvalidPrivilegeThrowsWhenPrivilegeIsInvalid)
437{
438 EXPECT_THROW(
439 throwForInvalidPrivilege("whatever"),
440 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
441}
442
443TEST_F(UserMgrInTest, ThrowForInvalidPrivilegeNoThrowWhenPrivilegeIsValid)
444{
445 EXPECT_NO_THROW(throwForInvalidPrivilege("priv-admin"));
446 EXPECT_NO_THROW(throwForInvalidPrivilege("priv-operator"));
447 EXPECT_NO_THROW(throwForInvalidPrivilege("priv-user"));
448 EXPECT_NO_THROW(throwForInvalidPrivilege("priv-noaccess"));
449}
450
Nan Zhouecf88762022-10-25 00:07:10 +0000451TEST_F(UserMgrInTest, ThrowForInvalidGroupsThrowsWhenGroupIsInvalid)
452{
453 EXPECT_THROW(
454 throwForInvalidGroups({"whatever"}),
455 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
456}
457
458TEST_F(UserMgrInTest, ThrowForInvalidGroupsNoThrowWhenGroupIsValid)
459{
460 EXPECT_NO_THROW(throwForInvalidGroups({"ipmi"}));
461 EXPECT_NO_THROW(throwForInvalidGroups({"ssh"}));
462 EXPECT_NO_THROW(throwForInvalidGroups({"redfish"}));
463 EXPECT_NO_THROW(throwForInvalidGroups({"web"}));
464}
465
Nan Zhouf25443e2022-10-25 00:07:11 +0000466TEST_F(UserMgrInTest, RenameUserOnSuccess)
467{
468 std::string username = "user001";
469 EXPECT_NO_THROW(
470 UserMgr::createUser(username, {"redfish", "ssh"}, "priv-user", true));
471 std::string newUsername = "user002";
472
473 EXPECT_NO_THROW(UserMgr::renameUser(username, newUsername));
474
475 // old username doesn't exist
476 EXPECT_THROW(getUserInfo(username),
477 sdbusplus::xyz::openbmc_project::User::Common::Error::
478 UserNameDoesNotExist);
479
480 UserInfoMap userInfo = getUserInfo(newUsername);
481 EXPECT_EQ(std::get<Privilege>(userInfo["UserPrivilege"]), "priv-user");
482 EXPECT_THAT(std::get<GroupList>(userInfo["UserGroups"]),
483 testing::UnorderedElementsAre("redfish", "ssh"));
484 EXPECT_EQ(std::get<UserEnabled>(userInfo["UserEnabled"]), true);
485
486 EXPECT_NO_THROW(UserMgr::deleteUser(newUsername));
487}
488
489TEST_F(UserMgrInTest, RenameUserThrowsInternalFailureIfExecuteUserModifyFails)
490{
491 std::string username = "user001";
492 EXPECT_NO_THROW(
493 UserMgr::createUser(username, {"redfish", "ssh"}, "priv-user", true));
494 std::string newUsername = "user002";
495
496 EXPECT_CALL(*this, executeUserRename(testing::StrEq(username),
497 testing::StrEq(newUsername)))
498 .WillOnce(testing::Throw(
499 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure()));
500 EXPECT_THROW(
501 UserMgr::renameUser(username, newUsername),
502 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
503
504 // The original user is unchanged
505 UserInfoMap userInfo = getUserInfo(username);
506 EXPECT_EQ(std::get<Privilege>(userInfo["UserPrivilege"]), "priv-user");
507 EXPECT_THAT(std::get<GroupList>(userInfo["UserGroups"]),
508 testing::UnorderedElementsAre("redfish", "ssh"));
509 EXPECT_EQ(std::get<UserEnabled>(userInfo["UserEnabled"]), true);
510
511 EXPECT_NO_THROW(UserMgr::deleteUser(username));
512}
513
514TEST_F(UserMgrInTest, DefaultUserModifyFailedWithInternalFailure)
515{
516 EXPECT_THROW(
517 UserMgr::executeUserRename("user0", "user1"),
518 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
Nan Zhoufef63032022-10-25 00:07:12 +0000519 EXPECT_THROW(
520 UserMgr::executeUserModify("user0", "ssh", true),
521 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
522}
523
524TEST_F(UserMgrInTest, UpdateGroupsAndPrivOnSuccess)
525{
526 std::string username = "user001";
527 EXPECT_NO_THROW(
528 UserMgr::createUser(username, {"redfish", "ssh"}, "priv-user", true));
529 EXPECT_NO_THROW(
530 updateGroupsAndPriv(username, {"ipmi", "ssh"}, "priv-admin"));
531 UserInfoMap userInfo = getUserInfo(username);
532 EXPECT_EQ(std::get<Privilege>(userInfo["UserPrivilege"]), "priv-admin");
533 EXPECT_THAT(std::get<GroupList>(userInfo["UserGroups"]),
534 testing::UnorderedElementsAre("ipmi", "ssh"));
535 EXPECT_EQ(std::get<UserEnabled>(userInfo["UserEnabled"]), true);
536 EXPECT_NO_THROW(UserMgr::deleteUser(username));
537}
538
539TEST_F(UserMgrInTest,
540 UpdateGroupsAndPrivThrowsInternalFailureIfExecuteUserModifyFail)
541{
542 std::string username = "user001";
543 EXPECT_NO_THROW(
544 UserMgr::createUser(username, {"redfish", "ssh"}, "priv-user", true));
545 EXPECT_CALL(*this, executeUserModify(testing::StrEq(username), testing::_,
546 testing::_))
547 .WillOnce(testing::Throw(
548 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure()));
549 EXPECT_THROW(
550 updateGroupsAndPriv(username, {"ipmi", "ssh"}, "priv-admin"),
551 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
552 EXPECT_NO_THROW(UserMgr::deleteUser(username));
Nan Zhouf25443e2022-10-25 00:07:11 +0000553}
554
Nan Zhou18031012022-11-10 22:24:58 +0000555TEST_F(UserMgrInTest, MinPasswordLengthReturnsIfValueIsTheSame)
556{
557 initializeAccountPolicy();
558 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
559 UserMgr::minPasswordLength(8);
560 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
561}
562
563TEST_F(UserMgrInTest,
564 MinPasswordLengthRejectsTooShortPasswordWithInvalidArgument)
565{
566 initializeAccountPolicy();
567 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
568 EXPECT_THROW(
569 UserMgr::minPasswordLength(minPasswdLength - 1),
570 sdbusplus::xyz::openbmc_project::Common::Error::InvalidArgument);
571 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
572}
573
574TEST_F(UserMgrInTest, MinPasswordLengthOnSuccess)
575{
576 initializeAccountPolicy();
577 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
578 UserMgr::minPasswordLength(16);
579 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 16);
580}
581
582TEST_F(UserMgrInTest, MinPasswordLengthOnFailure)
583{
584 EXPECT_NO_THROW(dumpStringToFile("whatever", tempPamConfigFile));
585 initializeAccountPolicy();
586 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
587 EXPECT_THROW(
588 UserMgr::minPasswordLength(16),
589 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
590 EXPECT_EQ(AccountPolicyIface::minPasswordLength(), 8);
591}
592
Nan Zhoua6ce1fa2022-10-25 00:07:14 +0000593TEST_F(UserMgrInTest, RememberOldPasswordTimesReturnsIfValueIsTheSame)
594{
595 initializeAccountPolicy();
596 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 0);
597 UserMgr::rememberOldPasswordTimes(8);
598 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 8);
599 UserMgr::rememberOldPasswordTimes(8);
600 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 8);
601}
602
603TEST_F(UserMgrInTest, RememberOldPasswordTimesOnSuccess)
604{
605 initializeAccountPolicy();
606 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 0);
607 UserMgr::rememberOldPasswordTimes(16);
608 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 16);
609}
610
611TEST_F(UserMgrInTest, RememberOldPasswordTimesOnFailure)
612{
613 EXPECT_NO_THROW(dumpStringToFile("whatever", tempPamConfigFile));
614 initializeAccountPolicy();
615 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 0);
616 EXPECT_THROW(
617 UserMgr::rememberOldPasswordTimes(16),
618 sdbusplus::xyz::openbmc_project::Common::Error::InternalFailure);
619 EXPECT_EQ(AccountPolicyIface::rememberOldPasswordTimes(), 0);
620}
621
raviteja-b8cc44052019-02-27 23:29:36 -0600622} // namespace user
623} // namespace phosphor