|
|
7711c0 |
From 5074b9b995f708fe57995267b40d3fedc4368c3b Mon Sep 17 00:00:00 2001
|
|
|
7711c0 |
From: John Snow <jsnow@redhat.com>
|
|
|
7711c0 |
Date: Fri, 22 Mar 2019 03:22:36 +0100
|
|
|
7711c0 |
Subject: [PATCH 069/163] iotests: Also test I/O over NBD TLS
|
|
|
7711c0 |
MIME-Version: 1.0
|
|
|
7711c0 |
Content-Type: text/plain; charset=UTF-8
|
|
|
7711c0 |
Content-Transfer-Encoding: 8bit
|
|
|
7711c0 |
|
|
|
7711c0 |
RH-Author: John Snow <jsnow@redhat.com>
|
|
|
7711c0 |
Message-id: <20190322032241.8111-24-jsnow@redhat.com>
|
|
|
7711c0 |
Patchwork-id: 85113
|
|
|
7711c0 |
O-Subject: [RHEL-7.7 qemu-kvm-rhev PATCH 23/28] iotests: Also test I/O over NBD TLS
|
|
|
7711c0 |
Bugzilla: 1691563
|
|
|
7711c0 |
RH-Acked-by: Max Reitz <mreitz@redhat.com>
|
|
|
7711c0 |
RH-Acked-by: Stefan Hajnoczi <stefanha@redhat.com>
|
|
|
7711c0 |
RH-Acked-by: Miroslav Rezanina <mrezanin@redhat.com>
|
|
|
7711c0 |
|
|
|
7711c0 |
From: Eric Blake <eblake@redhat.com>
|
|
|
7711c0 |
|
|
|
7711c0 |
Enhance test 233 to also perform I/O beyond the initial handshake.
|
|
|
7711c0 |
|
|
|
7711c0 |
Signed-off-by: Eric Blake <eblake@redhat.com>
|
|
|
7711c0 |
Message-Id: <20181118022403.2211483-1-eblake@redhat.com>
|
|
|
7711c0 |
Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>
|
|
|
7711c0 |
(cherry picked from commit bb39c47d70e84acf5066f79eba27ae5945b837be)
|
|
|
7711c0 |
Signed-off-by: John Snow <jsnow@redhat.com>
|
|
|
7711c0 |
Signed-off-by: Miroslav Rezanina <mrezanin@redhat.com>
|
|
|
7711c0 |
---
|
|
|
7711c0 |
tests/qemu-iotests/233 | 12 +++++++++++-
|
|
|
7711c0 |
tests/qemu-iotests/233.out | 10 ++++++++++
|
|
|
7711c0 |
2 files changed, 21 insertions(+), 1 deletion(-)
|
|
|
7711c0 |
|
|
|
7711c0 |
diff --git a/tests/qemu-iotests/233 b/tests/qemu-iotests/233
|
|
|
7711c0 |
index 46013ce..a4da60d 100755
|
|
|
7711c0 |
--- a/tests/qemu-iotests/233
|
|
|
7711c0 |
+++ b/tests/qemu-iotests/233
|
|
|
7711c0 |
@@ -62,7 +62,7 @@ tls_x509_create_client "ca2" "client2"
|
|
|
7711c0 |
echo
|
|
|
7711c0 |
echo "== preparing image =="
|
|
|
7711c0 |
_make_test_img 64M
|
|
|
7711c0 |
-
|
|
|
7711c0 |
+$QEMU_IO -c 'w -P 0x11 1m 1m' "$TEST_IMG" | _filter_qemu_io
|
|
|
7711c0 |
|
|
|
7711c0 |
echo
|
|
|
7711c0 |
echo "== check TLS client to plain server fails =="
|
|
|
7711c0 |
@@ -96,6 +96,16 @@ $QEMU_IMG info --image-opts \
|
|
|
7711c0 |
driver=nbd,host=$nbd_tcp_addr,port=$nbd_tcp_port,tls-creds=tls0 \
|
|
|
7711c0 |
2>&1 | sed "s/$nbd_tcp_port/PORT/g"
|
|
|
7711c0 |
|
|
|
7711c0 |
+echo
|
|
|
7711c0 |
+echo "== perform I/O over TLS =="
|
|
|
7711c0 |
+QEMU_IO_OPTIONS=$QEMU_IO_OPTIONS_NO_FMT
|
|
|
7711c0 |
+$QEMU_IO -c 'r -P 0x11 1m 1m' -c 'w -P 0x22 1m 1m' --image-opts \
|
|
|
7711c0 |
+ --object tls-creds-x509,dir=${tls_dir}/client1,endpoint=client,id=tls0 \
|
|
|
7711c0 |
+ driver=nbd,host=$nbd_tcp_addr,port=$nbd_tcp_port,tls-creds=tls0 \
|
|
|
7711c0 |
+ 2>&1 | _filter_qemu_io
|
|
|
7711c0 |
+
|
|
|
7711c0 |
+$QEMU_IO -f qcow2 -r -U -c 'r -P 0x22 1m 1m' "$TEST_IMG" | _filter_qemu_io
|
|
|
7711c0 |
+
|
|
|
7711c0 |
# success, all done
|
|
|
7711c0 |
echo "*** done"
|
|
|
7711c0 |
rm -f $seq.full
|
|
|
7711c0 |
diff --git a/tests/qemu-iotests/233.out b/tests/qemu-iotests/233.out
|
|
|
7711c0 |
index 616e923..94acd9b 100644
|
|
|
7711c0 |
--- a/tests/qemu-iotests/233.out
|
|
|
7711c0 |
+++ b/tests/qemu-iotests/233.out
|
|
|
7711c0 |
@@ -9,6 +9,8 @@ Generating a signed certificate...
|
|
|
7711c0 |
|
|
|
7711c0 |
== preparing image ==
|
|
|
7711c0 |
Formatting 'TEST_DIR/t.IMGFMT', fmt=IMGFMT size=67108864
|
|
|
7711c0 |
+wrote 1048576/1048576 bytes at offset 1048576
|
|
|
7711c0 |
+1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec)
|
|
|
7711c0 |
|
|
|
7711c0 |
== check TLS client to plain server fails ==
|
|
|
7711c0 |
qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': Denied by server for option 5 (starttls)
|
|
|
7711c0 |
@@ -27,4 +29,12 @@ disk size: unavailable
|
|
|
7711c0 |
== check TLS with different CA fails ==
|
|
|
7711c0 |
option negotiation failed: Verify failed: No certificate was found.
|
|
|
7711c0 |
qemu-img: Could not open 'driver=nbd,host=127.0.0.1,port=PORT,tls-creds=tls0': The certificate hasn't got a known issuer
|
|
|
7711c0 |
+
|
|
|
7711c0 |
+== perform I/O over TLS ==
|
|
|
7711c0 |
+read 1048576/1048576 bytes at offset 1048576
|
|
|
7711c0 |
+1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec)
|
|
|
7711c0 |
+wrote 1048576/1048576 bytes at offset 1048576
|
|
|
7711c0 |
+1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec)
|
|
|
7711c0 |
+read 1048576/1048576 bytes at offset 1048576
|
|
|
7711c0 |
+1 MiB, X ops; XX:XX:XX.X (XXX YYY/sec and XXX ops/sec)
|
|
|
7711c0 |
*** done
|
|
|
7711c0 |
--
|
|
|
7711c0 |
1.8.3.1
|
|
|
7711c0 |
|