mirror of
https://github.com/NLnetLabs/krill.git
synced 2026-10-01 05:44:52 +02:00
Refactor krill env var use, and allow KRILL_TEST_ANN to run krill with test announcements loaded.
This commit is contained in:
+36
-30
@@ -1,3 +1,4 @@
|
||||
use std::env;
|
||||
use std::sync::RwLock;
|
||||
|
||||
use chrono::Duration;
|
||||
@@ -10,7 +11,7 @@ use crate::commons::bgp::{
|
||||
Announcements, BgpAnalysisEntry, BgpAnalysisReport, IpRange, RisDumpError, RisDumpLoader,
|
||||
ValidatedAnnouncement,
|
||||
};
|
||||
use crate::constants::BGP_RIS_REFRESH_MINUTES;
|
||||
use crate::constants::{BGP_RIS_REFRESH_MINUTES, KRILL_ENV_TEST_ANN};
|
||||
|
||||
//------------ BgpAnalyser -------------------------------------------------
|
||||
|
||||
@@ -22,14 +23,18 @@ pub struct BgpAnalyser {
|
||||
|
||||
impl BgpAnalyser {
|
||||
pub fn new(ris_enabled: bool, ris_v4_uri: &str, ris_v6_uri: &str) -> Self {
|
||||
let dumploader = if ris_enabled {
|
||||
Some(RisDumpLoader::new(ris_v4_uri, ris_v6_uri))
|
||||
if env::var(KRILL_ENV_TEST_ANN).is_ok() {
|
||||
Self::with_test_announcements()
|
||||
} else {
|
||||
None
|
||||
};
|
||||
BgpAnalyser {
|
||||
dumploader,
|
||||
seen: RwLock::new(Announcements::default()),
|
||||
let dumploader = if ris_enabled {
|
||||
Some(RisDumpLoader::new(ris_v4_uri, ris_v6_uri))
|
||||
} else {
|
||||
None
|
||||
};
|
||||
BgpAnalyser {
|
||||
dumploader,
|
||||
seen: RwLock::new(Announcements::default()),
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -153,12 +158,28 @@ impl BgpAnalyser {
|
||||
BgpAnalysisReport::new(entries)
|
||||
}
|
||||
|
||||
#[cfg(test)]
|
||||
fn with_test_announcements(test_announcements: Vec<Announcement>) -> Self {
|
||||
fn test_announcements() -> Vec<Announcement> {
|
||||
use crate::test::announcement;
|
||||
|
||||
let mut res = vec![];
|
||||
|
||||
res.push(announcement("10.0.0.0/22 => 64496"));
|
||||
res.push(announcement("10.0.2.0/23 => 64496"));
|
||||
res.push(announcement("10.0.0.0/24 => 64496"));
|
||||
res.push(announcement("10.0.0.0/22 => 64497"));
|
||||
res.push(announcement("10.0.0.0/21 => 64497"));
|
||||
|
||||
res.push(announcement("192.168.0.0/26 => 64497"));
|
||||
res.push(announcement("192.168.0.0/26 => 64496"));
|
||||
|
||||
res.push(announcement("2001:DB8::/32 => 64498"));
|
||||
|
||||
res
|
||||
}
|
||||
|
||||
fn with_test_announcements() -> Self {
|
||||
let mut announcements = Announcements::default();
|
||||
if !test_announcements.is_empty() {
|
||||
announcements.update(test_announcements);
|
||||
}
|
||||
announcements.update(Self::test_announcements());
|
||||
BgpAnalyser {
|
||||
dumploader: None,
|
||||
seen: RwLock::new(announcements),
|
||||
@@ -208,27 +229,12 @@ mod tests {
|
||||
#[test]
|
||||
fn analyse_bgp() {
|
||||
let roa_authorizing = definition("10.0.0.0/22-23 => 64496");
|
||||
let ann_authz_1 = announcement("10.0.0.0/22 => 64496");
|
||||
let ann_authz_2 = announcement("10.0.2.0/23 => 64496");
|
||||
let ann_invalid_l = announcement("10.0.0.0/24 => 64496");
|
||||
let ann_invalid_a = announcement("10.0.0.0/22 => 64497");
|
||||
|
||||
let ann_irrelevant = announcement("192.168.0.0/26 => 64497");
|
||||
|
||||
let ann_not_found = announcement("10.0.0.0/21 => 64497");
|
||||
let roa_stale = definition("10.0.3.0/24 => 64497");
|
||||
let roa_disallowing = definition("10.0.4.0/24 => 0");
|
||||
|
||||
let resources = ResourceSet::from_strs("", "10.0.0.0/16", "").unwrap();
|
||||
|
||||
let analyser = BgpAnalyser::with_test_announcements(vec![
|
||||
ann_authz_1,
|
||||
ann_authz_2,
|
||||
ann_invalid_l,
|
||||
ann_invalid_a,
|
||||
ann_not_found,
|
||||
ann_irrelevant,
|
||||
]);
|
||||
let analyser = BgpAnalyser::with_test_announcements();
|
||||
|
||||
let report = analyser.analyse(&[roa_authorizing, roa_stale, roa_disallowing], &resources);
|
||||
|
||||
@@ -248,7 +254,7 @@ mod tests {
|
||||
|
||||
let resources = ResourceSet::from_strs("", "10.0.0.0/16", "").unwrap();
|
||||
|
||||
let analyser = BgpAnalyser::with_test_announcements(vec![]);
|
||||
let analyser = BgpAnalyser::new(false, "", "");
|
||||
let table = analyser.analyse(&[roa1, roa2, roa3], &resources);
|
||||
let table_entries = table.entries();
|
||||
assert_eq!(3, table_entries.len());
|
||||
|
||||
@@ -4,6 +4,13 @@ pub const KRILL_CLIENT_APP: &str = "Krill Client";
|
||||
|
||||
pub const KRILL_DEFAULT_CONFIG_FILE: &str = "./defaults/krill.conf";
|
||||
|
||||
pub const KRILL_ENV_TEST: &str = "KRILL_TEST";
|
||||
pub const KRILL_ENV_TEST_ANN: &str = "KRILL_TEST_ANN";
|
||||
pub const KRILL_ENV_REPO_ENABLED: &str = "KRILL_REPO_ENABLED";
|
||||
pub const KRILL_ENV_USE_TA: &str = "KRILL_USE_TA";
|
||||
pub const KRILL_ENV_LOG_LEVEL: &str = "KRILL_LOG_LEVEL";
|
||||
pub const KRILL_ENV_AUTH_TOKEN: &str = "KRILL_AUTH_TOKEN";
|
||||
|
||||
pub const CASERVER_DIR: &str = "cas";
|
||||
|
||||
pub const PUBSERVER_DFLT: &str = "0";
|
||||
|
||||
@@ -29,7 +29,9 @@ use crate::commons::remote::rfc6492;
|
||||
use crate::commons::remote::rfc8183;
|
||||
use crate::commons::remote::sigmsg::SignedMessage;
|
||||
use crate::commons::KrillResult;
|
||||
use crate::constants::{CHILD_CERTIFICATE_REISSUE_WEEKS, CHILD_CERTIFICATE_VALIDITY_YEARS};
|
||||
use crate::constants::{
|
||||
CHILD_CERTIFICATE_REISSUE_WEEKS, CHILD_CERTIFICATE_VALIDITY_YEARS, KRILL_ENV_TEST,
|
||||
};
|
||||
use crate::daemon::ca::events::ChildCertificateUpdates;
|
||||
use crate::daemon::ca::rc::PublishMode;
|
||||
use crate::daemon::ca::signing::CsrInfo;
|
||||
@@ -703,7 +705,7 @@ impl<S: Signer> CertAuth<S> {
|
||||
let (rcn, limit, csr) = request.unpack();
|
||||
let csr_info = CsrInfo::try_from(&csr)?;
|
||||
|
||||
if csr_info.contains_localhost() && env::var("KRILL_TEST").is_err() {
|
||||
if csr_info.contains_localhost() && env::var(KRILL_ENV_TEST).is_err() {
|
||||
return Err(Error::invalid_csr(
|
||||
"Cannot use localhost in certificate requests unless server uses TEST mode.",
|
||||
));
|
||||
|
||||
@@ -33,13 +33,13 @@ impl ConfigDefaults {
|
||||
3000
|
||||
}
|
||||
fn test_mode() -> bool {
|
||||
env::var("KRILL_TEST").is_ok()
|
||||
env::var(KRILL_ENV_TEST).is_ok()
|
||||
}
|
||||
fn repo_enabled() -> bool {
|
||||
env::var("KRILL_REPO_ENABLED").is_ok()
|
||||
env::var(KRILL_ENV_REPO_ENABLED).is_ok()
|
||||
}
|
||||
fn use_ta() -> bool {
|
||||
env::var("KRILL_USE_TA").is_ok()
|
||||
env::var(KRILL_ENV_USE_TA).is_ok()
|
||||
}
|
||||
fn https_mode() -> HttpsMode {
|
||||
HttpsMode::Generate
|
||||
@@ -54,7 +54,7 @@ impl ConfigDefaults {
|
||||
"https://localhost:3000/".to_string()
|
||||
}
|
||||
fn log_level() -> LevelFilter {
|
||||
match env::var("KRILL_LOG_LEVEL") {
|
||||
match env::var(KRILL_ENV_LOG_LEVEL) {
|
||||
Ok(level) => LevelFilter::from_str(&level).unwrap(),
|
||||
_ => LevelFilter::Info,
|
||||
}
|
||||
@@ -70,7 +70,7 @@ impl ConfigDefaults {
|
||||
}
|
||||
|
||||
fn auth_token() -> Token {
|
||||
match env::var("KRILL_AUTH_TOKEN") {
|
||||
match env::var(KRILL_ENV_AUTH_TOKEN) {
|
||||
Ok(token) => Token::from(token),
|
||||
Err(_) => {
|
||||
eprintln!("You MUST provide a value for the master API key, either by setting \"auth_token\" in the config file, or by setting the KRILL_AUTH_TOKEN environment variable.");
|
||||
@@ -391,7 +391,7 @@ impl Config {
|
||||
// Set KRILL_TEST env var so that it can easily be accessed without the need to pass
|
||||
// this setting down all over the application. Used by CertAuth in particular to allow
|
||||
// the use of 'localhost' in Certificate Sign Requests in test mode only.
|
||||
env::set_var("KRILL_TEST", "1");
|
||||
env::set_var(KRILL_ENV_TEST, "1");
|
||||
}
|
||||
|
||||
if !self.test_mode
|
||||
@@ -671,8 +671,8 @@ mod tests {
|
||||
// Config for auth token is required! If there is nothing in the conf
|
||||
// file, then an environment variable must be set.
|
||||
use std::env;
|
||||
env::set_var("KRILL_AUTH_TOKEN", "secret");
|
||||
env::set_var("KRILL_TEST", "1");
|
||||
env::set_var(KRILL_ENV_AUTH_TOKEN, "secret");
|
||||
env::set_var(KRILL_ENV_TEST, "1");
|
||||
|
||||
let c = Config::read_config("./defaults/krill.conf").unwrap();
|
||||
let expected_socket_addr: SocketAddr = ([127, 0, 0, 1], 3000).into();
|
||||
|
||||
Reference in New Issue
Block a user