From df6cfdd64ed864f770cf049c91ff7a63eaf9e693 Mon Sep 17 00:00:00 2001 From: Nikos Mavrogiannopoulos Date: Mon, 16 Mar 2026 20:08:46 +0100 Subject: [PATCH] tests: radius: auto-generate the freeradius config directory Signed-off-by: Nikos Mavrogiannopoulos --- meson.build | 13 +++++++++++++ tests/data/raddb/meson.build | 33 +++++++++++++++++++++++++++++++++ tests/meson.build | 31 ++++++++++++++++++++++++------- tests/radius | 2 +- tests/radius-config | 2 +- tests/radius-group | 2 +- tests/radius-multi-group | 2 +- tests/radius-otp | 2 +- 8 files changed, 75 insertions(+), 12 deletions(-) create mode 100644 tests/data/raddb/meson.build diff --git a/meson.build b/meson.build index a0250773..fbb08d47 100644 --- a/meson.build +++ b/meson.build @@ -124,6 +124,19 @@ if not opt_radius.disabled() endif endif +# Detect freeradius module directory (for test radiusd.conf generation) +# radius_libdir is the parent of the freeradius/ subdir (e.g. /usr/lib64) +radius_libdir = '/usr/lib' +foreach _pair : [['/usr/lib64/freeradius', '/usr/lib64'], + ['/usr/lib/freeradius', '/usr/lib'], + ['/usr/lib/x86_64-linux-gnu/freeradius', '/usr/lib/x86_64-linux-gnu'], + ['/usr/lib/aarch64-linux-gnu/freeradius', '/usr/lib/aarch64-linux-gnu']] + if fs.is_dir(_pair[0]) + radius_libdir = _pair[1] + break + endif +endforeach + # GSSAPI + libtasn1 gssapi_dep = dependency('', required: false) tasn1_dep = dependency('', required: false) diff --git a/tests/data/raddb/meson.build b/tests/data/raddb/meson.build new file mode 100644 index 00000000..c97f8be7 --- /dev/null +++ b/tests/data/raddb/meson.build @@ -0,0 +1,33 @@ +# Generate the raddb directory in the build tree. +# radiusd.conf is generated from .in with RADIUS_LIBDIR substituted; +# all other files are copied. A chmod step removes world/group write +# bits so FreeRADIUS does not refuse to load the configuration. + +_raddb_static = ['clients.conf', 'users', 'acct_users', + 'access_reject', 'accounting_response', 'access_challenge'] + +_raddb_conf = configure_file( + input: 'radiusd.conf.in', + output: 'radiusd.conf', + configuration: {'RADIUS_LIBDIR': radius_libdir}, +) + +_raddb_copies = [] +foreach _f : _raddb_static + _raddb_copies += configure_file(input: _f, output: _f, copy: true) +endforeach + +# FreeRADIUS refuses to start if any config file is group- or world-writable. +# meson's configure_file honours the process umask, which may be 0000 inside +# containers, producing 0666 files. Fix permissions after generation. +# build_by_default ensures 'ninja' builds this even without an explicit dep. +raddb_chmod_stamp = custom_target('raddb-chmod', + input: [_raddb_conf] + _raddb_copies, + output: 'raddb-chmod.stamp', + build_by_default: true, + command: ['sh', '-c', + 'chmod go-w "$(dirname "$1")" "$@" && touch @OUTPUT@', + '_dummy', # $0 (shell script name placeholder) + '@INPUT@', + ], +) diff --git a/tests/meson.build b/tests/meson.build index 93338ced..661dac3c 100644 --- a/tests/meson.build +++ b/tests/meson.build @@ -14,6 +14,17 @@ test_env.set('SERV', meson.build_root() / 'src' / 'ocserv') test_env.set('OCCTL', meson.build_root() / 'src' / 'occtl' / 'occtl') test_env.set('OCPASSWD', meson.build_root() / 'src' / 'ocpasswd' / 'ocpasswd') +# -------------------------------------------------------------------------- +# Generate raddb directory in the build tree +# radiusd.conf is generated from radiusd.conf.in with RADIUS_LIBDIR substituted. +# All other static files are copied so radiusd -d works. +# The subdir() call below outputs files into build/tests/data/raddb/. +# -------------------------------------------------------------------------- + +raddb_build_dir = meson.current_build_dir() / 'data' / 'raddb' +test_env.set('RADDB_DIR', raddb_build_dir) +subdir('data/raddb') + # -------------------------------------------------------------------------- # C unit tests # -------------------------------------------------------------------------- @@ -207,13 +218,6 @@ if get_option('root-tests') 'test-config-per-group-url-cert', 'test-multiple-client-ip', ] - if radcli_dep.found() - root_scripts += [ - 'radius', 'radius-group', 'radius-multi-group', - 'radius-otp', 'radius-config', - ] - endif - foreach s : root_scripts test(s, find_program(s), env: test_env, @@ -223,6 +227,19 @@ if get_option('root-tests') ) endforeach + if radcli_dep.found() + foreach s : ['radius', 'radius-group', 'radius-multi-group', + 'radius-otp', 'radius-config'] + test(s, find_program(s), + env: test_env, + timeout: 300, + is_parallel: false, + workdir: test_workdir, + depends: [raddb_chmod_stamp], + ) + endforeach + endif + test('test-script-multi-user', find_program('test-script-multi-user'), env: test_env, timeout: 700, diff --git a/tests/radius b/tests/radius index 18f81c0c..b7f260ca 100755 --- a/tests/radius +++ b/tests/radius @@ -80,7 +80,7 @@ USERNAME=test ${CMDNS2} ${IP} link set dev lo up # Run servers -${CMDNS2} ${RADIUSD} -d ${srcdir}/data/raddb/ -s -xx -l ${RADIUSLOG} & +${CMDNS2} ${RADIUSD} -d ${RADDB_DIR}/ -s -xx -l ${RADIUSLOG} & RADIUSPID=$! update_config radius.config diff --git a/tests/radius-config b/tests/radius-config index dc5182f2..6284692f 100755 --- a/tests/radius-config +++ b/tests/radius-config @@ -110,7 +110,7 @@ ${CMDNS2} ${IP} link set dev lo up # Run servers rm -f ${RADIUSLOG} -${CMDNS2} ${RADIUSD} -d ${srcdir}/data/raddb/ -s -xx -l ${RADIUSLOG} & +${CMDNS2} ${RADIUSD} -d ${RADDB_DIR}/ -s -xx -l ${RADIUSLOG} & RADIUSPID=$! update_config radius.config diff --git a/tests/radius-group b/tests/radius-group index 6df72b70..4e941ba5 100755 --- a/tests/radius-group +++ b/tests/radius-group @@ -86,7 +86,7 @@ OCCTL_SOCKET=./occtl-radius-group-$$.socket ${CMDNS2} ${IP} link set dev lo up # Run servers -${CMDNS2} ${RADIUSD} -d ${srcdir}/data/raddb/ -s -xx -l ${RADIUSLOG} & +${CMDNS2} ${RADIUSD} -d ${RADDB_DIR}/ -s -xx -l ${RADIUSLOG} & RADIUSPID=$! update_config radius-group.config diff --git a/tests/radius-multi-group b/tests/radius-multi-group index 27948f92..4cd9b7c9 100755 --- a/tests/radius-multi-group +++ b/tests/radius-multi-group @@ -86,7 +86,7 @@ OCCTL_SOCKET=./occtl-radius-group-$$.socket ${CMDNS2} ${IP} link set dev lo up # Run servers -${CMDNS2} ${RADIUSD} -d ${srcdir}/data/raddb/ -s -xx -l ${RADIUSLOG} & +${CMDNS2} ${RADIUSD} -d ${RADDB_DIR}/ -s -xx -l ${RADIUSLOG} & RADIUSPID=$! update_config radius-multi-group.config diff --git a/tests/radius-otp b/tests/radius-otp index f9e3881a..d23b23b8 100755 --- a/tests/radius-otp +++ b/tests/radius-otp @@ -93,7 +93,7 @@ OCCTL_SOCKET=./occtl-radius-otp-$$.socket ${CMDNS2} ${IP} link set dev lo up # Run servers -${CMDNS2} ${RADIUSD} -d ${srcdir}/data/raddb/ -s -xx -l ${RADIUSLOG} & +${CMDNS2} ${RADIUSD} -d ${RADDB_DIR}/ -s -xx -l ${RADIUSLOG} & RADIUSPID=$! update_config radius-otp.config