Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
43 changes: 43 additions & 0 deletions dirsrvtests/tests/suites/acl/conftest.py
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@

"""

import socket

import pytest

from lib389._constants import DEFAULT_SUFFIX, PW_DM
Expand All @@ -20,6 +22,47 @@
from lib389.idm.domain import Domain


@pytest.fixture(scope="module", autouse=True)
def configure_ipv4_mapped_hosts(request, topo):
"""Register the IPv4-mapped IPv6 address in /etc/hosts and remove it on teardown.

When DS binds on :: (dual-stack), IPv4 clients appear as ::ffff:x.x.x.x
at the socket layer. NSPR's PR_GetHostByAddr calls gethostbyaddr_r with
AF_INET6, and glibc-2.34 (RHEL 9.x) does not auto-unmap IPv4-mapped
addresses, so the plain IPv4 entry in /etc/hosts is not found and the
DNS keyword ACI evaluation fails with INSUFFICIENT_ACCESS.
Adding the ::ffff:<ip> form ensures the reverse lookup succeeds.
Comment thread
sourcery-ai[bot] marked this conversation as resolved.
"""
host = topo.standalone.host
ip = socket.gethostbyname(host)
mapped = f"::ffff:{ip}"

with open("/etc/hosts") as f:
already_present = any(
line.split()[0] == mapped and host in line.split()
for line in f
if line.split() and not line.startswith('#')
)

if already_present:
yield
return

entry = f"{mapped} {host}\n"
with open("/etc/hosts", "a") as f:
Comment thread
progier389 marked this conversation as resolved.
f.write(entry)

def remove_entry():
with open("/etc/hosts") as f:
lines = f.readlines()
with open("/etc/hosts", "w") as f:
f.writelines(line for line in lines if line != entry)

request.addfinalizer(remove_entry)

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Tear down seems still present.

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Please remove the 54-63 lines to avoid risking /etc/hosts corruption if the process get somehow killed while rewriting it


yield


@pytest.fixture(scope="function")
def aci_of_user(request, topo):
"""
Expand Down
Loading