1 #! /usr/bin/ksh -p
2 #
3 # CDDL HEADER START
4 #
5 # The contents of this file are subject to the terms of the
6 # Common Development and Distribution License (the "License").
7 # You may not use this file except in compliance with the License.
8 #
9 # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
10 # or http://www.opensolaris.org/os/licensing.
11 # See the License for the specific language governing permissions
12 # and limitations under the License.
13 #
14 # When distributing Covered Code, include this CDDL HEADER in each
15 # file and include the License file at usr/src/OPENSOLARIS.LICENSE.
16 # If applicable, add the following below this CDDL HEADER, with the
17 # fields enclosed by brackets "[]" replaced with your own identifying
18 # information: Portions Copyright [yyyy] [name of copyright owner]
19 #
20 # CDDL HEADER END
21 #
22
23 #
24 # Copyright 2008 Sun Microsystems, Inc. All rights reserved.
25 # Use is subject to license terms.
26 #
27
28 #
29 # start __stf_assertion__
30 #
31 # ASSERTION: context_036
32 # DESCRIPTION:
33 # svc.startd will start a method using the limit privilege set specified
34 # by the limit_privileges attribute of the method_credential element.
35 #
36 # end __stf_assertion__
37 #
38
39 . ${STF_TOOLS}/include/stf.kshlib
40 . ${STF_SUITE}/include/gltest.kshlib
41 . ${STF_SUITE}/include/svc.startd_config.kshlib
42 . ${STF_SUITE}/tests/svc.startd/include/svc.startd_common.kshlib
43
44 typeset service_setup=0
45 function cleanup {
46 common_cleanup
47 }
48
49 trap cleanup 0 1 2 15
50
51 readonly ME=$(whence -p ${0})
52 readonly MYLOC=$(dirname ${ME})
53
54 DATA=$MYLOC
55
56 readonly registration_template=$DATA/service_036.xml
57
58 extract_assertion_info $ME
59
60 # remove all dtrace privileges
61 typeset limitprivs=all
62 typeset priv=
63 for priv in $(ppriv -l | grep dtrace); do
64 limitprivs=$limitprivs,-$priv
65 done
66
67
68 # make sure that the svc.startd is running
69 verify_daemon
70 if [ $? -ne 0 ]; then
71 print -- "--DIAG: $assertion: svc.startd is not executing. Cannot "
72 print -- " continue"
73 exit $STF_UNRESOLVED
74 fi
75
76 # Make sure the environment is clean - the test service isn't running
77 print -- "--INFO: Cleanup any old $test_FMRI state"
78 service_cleanup $test_service
79 if [ $? -ne 0 ]; then
80 print -- "--DIAG: $assertion: cleanup of a previous instance failed"
81 exit $STF_UNRESOLVED
82 fi
83
84 print -- "--INFO: create world read/writeable log file for the service"
85 rm -f $service_log
86 touch $service_log
87 if [ $? -ne 0 ]; then
88 print -- "--DIAG: $assertion: could not create log file"
89 exit $STF_UNRESOLVED
90 fi
91 chmod a+rw $service_log
92 if [ $? -ne 0 ]; then
93 print -- "--DIAG: $assertion: could not make log file world writeable"
94 exit $STF_UNRESOLVED
95 fi
96
97 print -- "--INFO: Make sure the $RUNDIR is world r/w/x"
98 chmod a+rwx $RUNDIR
99 if [ $? -ne 0 ]; then
100 print -- "--DIAG: $assertion: could not make $RUNDIR mode 777"
101 exit $STF_UNRESOLVED
102 fi
103
104 print -- "--INFO: generating manifest for importation into repository"
105 manifest_generate $registration_template \
106 TEST_SERVICE=$test_service \
107 TEST_INSTANCE=$test_instance \
108 SERVICE_APP=$service_app \
109 LOGFILE=$service_log \
110 LIMIT_PRIVSET="$limitprivs" \
111 STATEFILE=$service_state > $registration_file
112 manifest_zone_clean $registration_file
113
114 print -- "--INFO: Importing service into repository"
115 manifest_purgemd5 $registration_file
116 svccfg -v import $registration_file >$svccfg_errfile 2>&1
117
118 if [ $? -ne 0 ]; then
119 print -- "--DIAG: $assertion: Unable to import the service $test_FMRI"
120 print -- " error messages from svccfg: \"$(cat $svccfg_errfile)\""
121 exit $STF_UNRESOLVED
122 fi
123 service_setup=1
124
125 print -- "--INFO: Wait for $test_FMRI to come online"
126 service_wait_state $test_FMRI online
127 if [ $? -ne 0 ]; then
128 print -- "--DIAG: $assertion: Service $test_FMRI did not go online"
129 exit $STF_FAIL
130 fi
131
132 print -- "--INFO: Checking start methods credential removed dtrace limit set"
133 line=`grep_logline_entry $test_service $test_instance start limit_privileges`
134 if [ $? -ne 0 ]; then
135 print -- "--DIAG: Could not find limit privileges line from "
136 print -- " start method '${line}'"
137 exit $STF_FAIL
138 fi
139
140 if [ "${line%dtrace*}" != "${line}" ]; then
141 print -- "--DIAG: privileges '$line' had 'dtrace' entries"
142 exit $STF_FAIL
143 fi
144
145 print -- "--INFO: Cleaning up service"
146 cleanup
147
148 exit $STF_PASS