3 # Copyright (C) 2019 Red Hat Inc.
5 # Redistribution and use in source and binary forms, with or without
6 # modification, are permitted provided that the following conditions are
9 # * Redistributions of source code must retain the above copyright
10 # notice, this list of conditions and the following disclaimer.
12 # * Redistributions in binary form must reproduce the above copyright
13 # notice, this list of conditions and the following disclaimer in the
14 # documentation and/or other materials provided with the distribution.
16 # * Neither the name of Red Hat nor the names of its contributors may be
17 # used to endorse or promote products derived from this software without
18 # specific prior written permission.
20 # THIS SOFTWARE IS PROVIDED BY RED HAT AND CONTRIBUTORS ''AS IS'' AND
21 # ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO,
22 # THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A
23 # PARTICULAR PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL RED HAT OR
24 # CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
25 # SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
26 # LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
27 # USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND
28 # ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY,
29 # OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT
30 # OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
37 requires qemu-img
--version
39 # Does the nbdkit binary support TLS?
40 if ! nbdkit
--dump-config |
grep -sq tls
=yes; then
41 echo "$0: nbdkit built without TLS support"
45 # Does the nbd plugin support TLS?
46 if ! nbdkit
--dump-plugin nbd |
grep -sq libnbd_tls
=1; then
47 echo "$0: nbd plugin built without TLS support"
51 # Did we create the PKI files?
52 # Probably 'certtool' is missing.
54 if [ ! -f "$pkidir/ca-cert.pem" ]; then
55 echo "$0: PKI files were not created by the test harness"
61 pid1
="test-nbd-tls.pid1"
62 pid2
="test-nbd-tls.pid2"
64 files
="$sock1 $sock2 $pid1 $pid2 nbd-tls.out"
66 cleanup_fn
rm -f $files
68 # Run encrypted server
69 start_nbdkit
-P "$pid1" -U "$sock1" \
70 --tls=require
--tls-certificates="$pkidir" example1
72 # Run nbd plugin as intermediary
73 LIBNBD_DEBUG
=1 start_nbdkit
-P "$pid2" -U "$sock2" --tls=off \
74 nbd tls
=require tls-certificates
="$pkidir" socket
="$sock1"
76 # Run unencrypted client
77 qemu-img info
--output=json
-f raw
"nbd+unix:///?socket=$sock2" > nbd-tls.out
81 grep -sq '"format": *"raw"' nbd-tls.out
82 grep -sq '"virtual-size": *104857600\b' nbd-tls.out