1 ;;; GNU Guix --- Functional package management for GNU
2 ;;; Copyright © 2016, 2017, 2018, 2019, 2020 Ludovic Courtès <ludo@gnu.org>
3 ;;; Copyright © 2018 Clément Lassieur <clement@lassieur.org>
5 ;;; This file is part of GNU Guix.
7 ;;; GNU Guix is free software; you can redistribute it and/or modify it
8 ;;; under the terms of the GNU General Public License as published by
9 ;;; the Free Software Foundation; either version 3 of the License, or (at
10 ;;; your option) any later version.
12 ;;; GNU Guix is distributed in the hope that it will be useful, but
13 ;;; WITHOUT ANY WARRANTY; without even the implied warranty of
14 ;;; MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
15 ;;; GNU General Public License for more details.
17 ;;; You should have received a copy of the GNU General Public License
18 ;;; along with GNU Guix. If not, see <http://www.gnu.org/licenses/>.
20 (define-module (gnu tests base)
21 #:use-module (gnu tests)
22 #:use-module (gnu system)
23 #:use-module (gnu system shadow)
24 #:use-module (gnu system nss)
25 #:use-module (gnu system vm)
26 #:use-module (gnu services)
27 #:use-module (gnu services base)
28 #:use-module (gnu services dbus)
29 #:use-module (gnu services avahi)
30 #:use-module (gnu services mcron)
31 #:use-module (gnu services shepherd)
32 #:use-module (gnu services networking)
33 #:use-module (gnu packages base)
34 #:use-module (gnu packages bash)
35 #:use-module (gnu packages imagemagick)
36 #:use-module (gnu packages ocr)
37 #:use-module (gnu packages package-management)
38 #:use-module (gnu packages linux)
39 #:use-module (gnu packages tmux)
40 #:use-module (guix gexp)
41 #:use-module (guix store)
42 #:use-module (guix monads)
43 #:use-module (guix packages)
44 #:use-module (srfi srfi-1)
45 #:use-module (ice-9 match)
46 #:export (run-basic-test
54 (simple-operating-system))
57 (define* (run-basic-test os command #:optional (name "basic")
58 #:key initialization root-password)
59 "Return a derivation called NAME that tests basic features of the OS started
60 using COMMAND, a gexp that evaluates to a list of strings. Compare some
61 properties of running system to what's declared in OS, an <operating-system>.
63 When INITIALIZATION is true, it must be a one-argument procedure that is
64 passed a gexp denoting the marionette, and it must return gexp that is
65 inserted before the first test. This is used to introduce an extra
66 initialization step, such as entering a LUKS passphrase.
68 When ROOT-PASSWORD is true, enter it as the root password when logging in.
69 Otherwise assume that there is no password for root."
72 (fold-services (operating-system-services os)
73 #:target-type special-files-service-type)))
76 (match (package-transitive-propagated-inputs guix)
77 (((labels packages) ...)
78 (cons guix packages))))
81 (with-imported-modules '((gnu build marionette)
82 (guix build syscalls))
84 (use-modules (gnu build marionette)
92 (make-marionette #$command))
100 (initialization #~marionette))
103 (match (marionette-eval '(uname) marionette)
104 (#("Linux" host-name version _ architecture)
105 (and (string=? host-name
106 #$(operating-system-host-name os))
107 (string-prefix? #$(package-version
108 (operating-system-kernel os))
110 (string-prefix? architecture %host-type)))))
112 ;; Shepherd reads the config file *before* binding its control
113 ;; socket, so /var/run/shepherd/socket might not exist yet when the
114 ;; 'marionette' service is started.
115 (test-assert "shepherd socket ready"
118 (use-modules (gnu services herd))
120 (cond ((file-exists? (%shepherd-socket-file))
129 (test-eq "stdin is /dev/null"
131 ;; Make sure services can no longer read from stdin once the
132 ;; system has booted.
135 (use-modules (gnu services herd))
136 (start 'user-processes)
137 ((@@ (gnu services herd) eval-there)
138 '(let ((result (read (current-input-port))))
139 (if (eof-object? result)
144 (test-assert "shell and user commands"
145 ;; Is everything in $PATH?
146 (zero? (marionette-eval '(system "
155 (test-equal "special files"
159 (use-modules (ice-9 match))
163 (list file (readlink file))))
167 (test-assert "accounts"
168 (let ((users (marionette-eval '(begin
169 (use-modules (ice-9 match))
170 (let loop ((result '()))
172 (#f (reverse result))
173 (x (loop (cons x result))))))
177 (list (passwd:name user)
181 #$@(map (lambda (account)
182 `(list ,(user-account-name account)
183 ,(user-account-home-directory account)))
184 (operating-system-user-accounts os))))))
186 (test-assert "shepherd services"
187 (let ((services (marionette-eval
189 (use-modules (gnu services herd))
191 (map (compose car live-service-provision)
195 (pk 'services services)
196 '(root #$@(operating-system-shepherd-service-names os)))))
198 (test-equal "/var/log/messages is not world-readable"
199 #o640 ;<https://bugs.gnu.org/40405>
201 (wait-for-file "/var/log/messages" marionette
203 (marionette-eval '(stat:perms (lstat "/var/log/messages"))
208 '#$(map user-account-home-directory
209 (filter user-account-create-home-directory?
210 (operating-system-user-accounts os)))))
213 (use-modules (gnu services herd) (srfi srfi-1))
215 ;; Home directories are supposed to exist once 'user-homes'
217 (start-service 'user-homes)
219 (every (lambda (home)
220 (and (file-exists? home)
221 (file-is-directory? home)))
225 (test-assert "skeletons in home directories"
227 '#$(filter-map (lambda (account)
228 (and (user-account-create-home-directory?
230 (not (user-account-system? account))
231 (list (user-account-name account)
232 (user-account-home-directory
234 (operating-system-user-accounts os))))
237 (use-modules (guix build utils) (srfi srfi-1)
238 (ice-9 ftw) (ice-9 match))
242 ;; Make sure HOME has all the skeletons...
243 (and (null? (lset-difference string=?
244 (scandir "/etc/skel/")
247 ;; ... and that everything is user-owned.
248 (let* ((pw (getpwnam user))
249 (uid (passwd:uid pw))
250 (gid (passwd:gid pw))
252 (define (user-owned? file)
253 (= uid (stat:uid (lstat file))))
255 (and (= uid (stat:uid st))
256 (eq? 'directory (stat:type st))
259 #:directories? #t)))))))
263 (test-equal "permissions on /root"
265 (let ((root-home #$(any (lambda (account)
266 (and (zero? (user-account-uid account))
267 (user-account-home-directory
269 (operating-system-user-accounts os))))
270 (stat:perms (marionette-eval `(stat ,root-home) marionette))))
272 (test-equal "ownership and permissions of /var/empty"
274 (let ((st (marionette-eval `(stat "/var/empty") marionette)))
275 (list (stat:uid st) (stat:gid st)
278 (test-equal "no extra home directories"
281 ;; Make sure the home directories that are not supposed to be
282 ;; created are indeed not created.
284 '#$(filter-map (lambda (user)
286 (user-account-create-home-directory?
288 (user-account-home-directory user)))
289 (operating-system-user-accounts os))))
292 (use-modules (srfi srfi-1))
294 ;; Note: Do not flag "/var/empty".
296 ',(remove (cut string-prefix? "/var/" <>)
300 (test-equal "login on tty1"
303 (marionette-control "sendkey ctrl-alt-f1" marionette)
304 ;; Wait for the 'term-tty1' service to be running (using
305 ;; 'start-service' is the simplest and most reliable way to do
309 (use-modules (gnu services herd))
310 (start-service 'term-tty1))
314 (let ((password #$root-password))
317 (marionette-type "root\n" marionette)
318 (wait-for-screen-text marionette
320 (string-contains text "Password"))
322 #$(file-append ocrad "/bin/ocrad"))
323 (marionette-type (string-append password "\n\n")
325 (marionette-type "root\n\n" marionette)))
326 (marionette-type "id -un > logged-in\n" marionette)
328 ;; It can take a while before the shell commands are executed.
329 (marionette-eval '(use-modules (rnrs io ports)) marionette)
330 (wait-for-file "/root/logged-in" marionette
331 #:read 'get-string-all)))
333 (test-equal "getlogin on tty1"
336 ;; Assume we logged in in the previous test and type.
337 (marionette-type "guile -c '(write (getlogin))' > /root/login-id.tmp\n"
339 (marionette-type "mv /root/login-id{.tmp,}\n"
342 ;; It can take a while before the shell commands are executed.
343 (marionette-eval '(use-modules (rnrs io ports)) marionette)
344 (wait-for-file "/root/login-id" marionette
345 #:read 'get-string-all)))
347 ;; There should be one utmpx entry for the user logged in on tty1.
348 (test-equal "utmpx entry"
349 '(("root" "tty1" #f))
352 (use-modules (guix build syscalls)
355 (filter-map (lambda (entry)
356 (and (equal? (login-type USER_PROCESS)
357 (utmpx-login-type entry))
358 (list (utmpx-user entry) (utmpx-line entry)
359 (utmpx-host entry))))
363 ;; Likewise for /var/log/wtmp (used by 'last').
364 (test-assert "wtmp entry"
365 (match (marionette-eval
367 (use-modules (guix build syscalls)
370 (define (entry->list entry)
371 (list (utmpx-user entry) (utmpx-line entry)
372 (utmpx-host entry) (utmpx-login-type entry)))
374 (call-with-input-file "/var/log/wtmp"
376 (let loop ((result '()))
377 (if (eof-object? (peek-char port))
378 (map entry->list (reverse result))
379 (loop (cons (read-utmpx port) result)))))))
381 (((users lines hosts types) ..1)
382 (every (lambda (type)
383 (eqv? type (login-type LOGIN_PROCESS)))
386 (test-assert "host name resolution"
387 (match (marionette-eval
389 ;; Wait for nscd or our requests go through it.
390 (use-modules (gnu services herd))
391 (start-service 'nscd)
393 (list (getaddrinfo "localhost")
394 (getaddrinfo #$(operating-system-host-name os))))
396 ((((? vector?) ..1) ((? vector?) ..1))
399 (pk 'failure x #f))))
401 (test-equal "nscd invalidate action"
403 (marionette-eval '(with-shepherd-action 'nscd ('invalidate "hosts")
408 ;; FIXME: The 'invalidate' action can't reliably obtain the exit
409 ;; code of 'nscd' so skip this test.
411 (test-equal "nscd invalidate action, wrong table"
413 (marionette-eval '(with-shepherd-action 'nscd ('invalidate "xyz")
418 (test-equal "host not found"
421 '(false-if-exception (getaddrinfo "does-not-exist"))
426 (marionette-eval '(let ((before (setlocale LC_ALL "en_US.utf8")))
427 (setlocale LC_ALL before))
430 (test-eq "/run/current-system is a GC root"
432 (marionette-eval '(begin
433 ;; Make sure the (guix …) modules are found.
434 (eval-when (expand load eval)
436 (append (map (lambda (package)
437 (string-append package
439 (effective-version)))
443 (use-modules (srfi srfi-34) (guix store))
445 (let ((system (readlink "/run/current-system")))
446 (guard (c ((store-protocol-error? c)
447 (and (file-exists? system)
450 (delete-paths store (list system))
454 ;; This symlink is currently unused, but better have it point to the
456 ;; <https://lists.gnu.org/archive/html/guix-devel/2016-08/msg01641.html>.
457 (test-equal "/var/guix/gcroots/profiles is a valid symlink"
459 (marionette-eval '(readlink "/var/guix/gcroots/profiles")
462 (test-equal "guix-daemon set-http-proxy action"
464 (marionette-eval '(with-shepherd-action 'guix-daemon
465 ('set-http-proxy "http://localhost:8118")
470 (test-equal "guix-daemon set-http-proxy action, clear"
472 (marionette-eval '(with-shepherd-action 'guix-daemon
478 (test-assert "screendump"
480 (marionette-control (string-append "screendump " #$output
483 (file-exists? "tty1.ppm")))
485 (test-assert "screen text"
486 (let ((text (marionette-screen-text marionette
490 ;; Check whether the welcome message and shell prompt are
491 ;; displayed. Note: OCR confuses "y" and "V" for instance, so
492 ;; we cannot reliably match the whole text.
493 (and (string-contains text "This is the GNU")
494 (string-contains text
497 #$(operating-system-host-name os))))))
500 (exit (= (test-runner-fail-count (test-runner-current)) 0)))))
502 (gexp->derivation name test))
504 (define %test-basic-os
508 "Instrument %SIMPLE-OS, run it in a VM, and run a series of basic
509 functionality tests.")
511 (let* ((os (marionette-operating-system
513 #:imported-modules '((gnu services herd)
514 (guix combinators))))
515 (vm (virtual-machine os)))
516 ;; XXX: Add call to 'virtualized-operating-system' to get the exact same
517 ;; set of services as the OS produced by
518 ;; 'system-qemu-image/shared-store-script'.
519 (run-basic-test (virtualized-operating-system os '())
527 (define (run-halt-test vm)
528 ;; As reported in <http://bugs.gnu.org/26931>, running tmux would previously
529 ;; lead the 'stop' method of 'user-processes' to an infinite loop, with the
530 ;; tmux server process as a zombie that remains in the list of processes.
531 ;; This test reproduces this scenario.
533 (with-imported-modules '((gnu build marionette))
535 (use-modules (gnu build marionette))
538 (make-marionette '(#$vm)))
541 #$(file-append ocrad "/bin/ocrad"))
543 ;; Wait for tty1 and log in.
544 (marionette-eval '(begin
545 (use-modules (gnu services herd))
546 (start-service 'term-tty1))
548 (marionette-type "root\n" marionette)
549 (wait-for-screen-text marionette
551 (string-contains text "root@komputilo"))
554 ;; Start tmux and wait for it to be ready.
555 (marionette-type "tmux new-session 'echo 1 > /ready; bash'\n"
557 (wait-for-file "/ready" marionette)
559 ;; Make sure to stop the test after a while.
560 (sigaction SIGALRM (lambda _
561 (format (current-error-port)
562 "FAIL: Time is up, but VM still running.\n")
566 ;; Get debugging info.
567 (marionette-eval '(current-output-port
568 (open-file "/dev/console" "w0"))
570 (marionette-eval '(system* #$(file-append procps "/bin/ps")
571 "-eo" "pid,ppid,stat,comm")
574 ;; See if 'halt' actually works.
575 (marionette-eval '(system* "/run/current-system/profile/sbin/halt")
578 ;; If we reach this line, that means the VM was properly stopped in
581 (call-with-output-file #$output
583 (display "success!" port))))))
585 (gexp->derivation "halt" test))
591 "Use the 'halt' command and make sure it succeeds and does not get stuck
592 in a loop. See <http://bugs.gnu.org/26931>.")
594 (let ((os (marionette-operating-system
597 (packages (cons tmux %base-packages)))
598 #:imported-modules '((gnu services herd)
599 (guix combinators)))))
600 (run-halt-test (virtual-machine os))))))
604 ;;; Cleanup of /tmp, /var/run, etc.
608 (simple-operating-system
609 (simple-service 'dirty-things
611 (let ((script (plain-file
612 "create-utf8-file.sh"
614 "echo $0: dirtying /tmp...\n"
617 "exec touch /tmp/λαμβδα"))))
618 (with-imported-modules '((guix build utils))
621 #$(file-append coreutils "/bin"))
622 (invoke #$(file-append bash "/bin/sh")
625 (define (run-cleanup-test name)
627 (marionette-operating-system %cleanup-os
628 #:imported-modules '((gnu services herd)
629 (guix combinators))))
631 (with-imported-modules '((gnu build marionette))
633 (use-modules (gnu build marionette)
638 (make-marionette (list #$(virtual-machine os))))
643 (test-begin "cleanup")
645 (test-assert "dirty service worked"
646 (marionette-eval '(file-exists? "/witness") marionette))
648 (test-equal "/tmp cleaned up"
650 (marionette-eval '(begin
651 (use-modules (ice-9 ftw))
656 (exit (= (test-runner-fail-count (test-runner-current)) 0)))))
658 (gexp->derivation "cleanup" test))
660 (define %test-cleanup
661 ;; See <https://bugs.gnu.org/26353>.
664 (description "Make sure the 'cleanup' service can remove files with
665 non-ASCII names from /tmp.")
666 (value (run-cleanup-test name))))
674 ;; System with an mcron service, with one mcron job for "root" and one mcron
675 ;; job for an unprivileged user.
676 (let ((job1 #~(job '(next-second '(0 5 10 15 20 25 30 35 40 45 50 55))
678 (unless (file-exists? "witness")
679 (call-with-output-file "witness"
681 (display (list (getuid) (getgid)) port)))))))
682 (job2 #~(job next-second-from
684 (call-with-output-file "witness"
686 (display (list (getuid) (getgid)) port))))
688 (job3 #~(job next-second-from ;to test $PATH
689 "touch witness-touch")))
690 (simple-operating-system
691 (service mcron-service-type
692 (mcron-configuration (jobs (list job1 job2 job3)))))))
694 (define (run-mcron-test name)
696 (marionette-operating-system
698 #:imported-modules '((gnu services herd)
699 (guix combinators))))
702 (with-imported-modules '((gnu build marionette))
704 (use-modules (gnu build marionette)
709 (make-marionette (list #$(virtual-machine os))))
716 (test-assert "service running"
719 (use-modules (gnu services herd))
720 (start-service 'mcron))
723 ;; Make sure root's mcron job runs, has its cwd set to "/root", and
724 ;; runs with the right UID/GID.
725 (test-equal "root's job"
727 (wait-for-file "/root/witness" marionette))
729 ;; Likewise for Alice's job. We cannot know what its GID is since
730 ;; it's chosen by 'groupadd', but it's strictly positive.
731 (test-assert "alice's job"
732 (match (wait-for-file "/home/alice/witness" marionette)
736 ;; Last, the job that uses a command; allows us to test whether
738 (test-equal "root's job with command"
740 (wait-for-file "/root/witness-touch" marionette
741 #:read '(@ (ice-9 rdelim) read-string)))
743 ;; Make sure the 'schedule' action is accepted.
744 (test-equal "schedule action"
746 (marionette-eval '(with-shepherd-action 'mcron ('schedule) result
751 (exit (= (test-runner-fail-count (test-runner-current)) 0)))))
753 (gexp->derivation name test))
758 (description "Make sure the mcron service works as advertised.")
759 (value (run-mcron-test name))))
763 ;;; Avahi and NSS-mDNS.
769 (name-service-switch %mdns-host-lookup-nss)
770 (services (cons* (service avahi-service-type
771 (avahi-configuration (debug? #t)))
773 (service dhcp-client-service-type) ;needed for multicast
775 ;; Enable heavyweight debugging output.
776 (modify-services (operating-system-user-services
778 (nscd-service-type config
779 => (nscd-configuration
782 (log-file "/dev/console")))
783 (syslog-service-type config
785 (syslog-configuration
790 "*.* /dev/console\n")))))))))
792 (define (run-nss-mdns-test)
793 ;; Test resolution of '.local' names via libc. Start the marionette service
794 ;; *after* nscd. Failing to do that, libc will try to connect to nscd,
795 ;; fail, then never try again (see '__nss_not_use_nscd_hosts' in libc),
796 ;; leading to '.local' resolution failures.
798 (marionette-operating-system
800 #:requirements '(nscd)
801 #:imported-modules '((gnu services herd)
802 (guix combinators))))
804 (define mdns-host-name
805 (string-append (operating-system-host-name os)
809 (with-imported-modules '((gnu build marionette))
811 (use-modules (gnu build marionette)
817 (make-marionette (list #$(virtual-machine os))))
824 (test-assert "nscd PID file is created"
827 (use-modules (gnu services herd))
828 (start-service 'nscd))
831 (test-assert "nscd is listening on its socket"
833 ;; XXX: Work around a race condition in nscd: nscd creates its
834 ;; PID file before it is listening on its socket.
835 '(let ((sock (socket PF_UNIX SOCK_STREAM 0)))
839 (connect sock AF_UNIX "/var/run/nscd/socket")
841 (format #t "nscd is ready~%")
844 (format #t "waiting for nscd...~%")
849 (test-assert "avahi is running"
852 (use-modules (gnu services herd))
853 (start-service 'avahi-daemon))
856 (test-assert "network is up"
859 (use-modules (gnu services herd))
860 (start-service 'networking))
863 (test-equal "avahi-resolve-host-name"
867 "/run/current-system/profile/bin/avahi-resolve-host-name"
868 "-v" #$mdns-host-name)
871 (test-equal "avahi-browse"
874 '(system* "avahi-browse" "-avt")
877 (test-assert "getaddrinfo .local"
878 ;; Wait for the 'avahi-daemon' service and perform a resolution.
879 (match (marionette-eval
880 '(getaddrinfo #$mdns-host-name)
882 (((? vector? addrinfos) ..1)
883 (pk 'getaddrinfo addrinfos)
884 (and (any (lambda (ai)
885 (= AF_INET (addrinfo:fam ai)))
888 (= AF_INET6 (addrinfo:fam ai)))
891 (test-assert "gethostbyname .local"
892 (match (pk 'gethostbyname
893 (marionette-eval '(gethostbyname #$mdns-host-name)
896 (and (string=? (hostent:name result) #$mdns-host-name)
897 (= (hostent:addrtype result) AF_INET)))))
901 (exit (= (test-runner-fail-count (test-runner-current)) 0)))))
903 (gexp->derivation "nss-mdns" test))
905 (define %test-nss-mdns
909 "Test Avahi's multicast-DNS implementation, and in particular, test its
910 glibc name service switch (NSS) module.")
911 (value (run-nss-mdns-test))))