Files
finit/test/dbus-broker.sh
T
Joachim Wiberg 127049d925 test: Finit against a real dbus-daemon
The other dbus-*.sh tests drive libink's own client, so the wire format
was only ever checked against the implementation that wrote it, and the
broker path had no coverage at all.  Every bug found in it so far was
found by hand on a target.

Let the dbus plugin bring up a real dbus-daemon, wait for Finit to
claim org.finit, then talk to Finit with dbus-send, which shares no
code with us.  The privileged call is the interesting one: it can only
be answered by parking the call and asking the broker who sent it.
The bus reads the policy Finit installs, so a malformed org.finit.conf
fails here rather than on a target.

Tests no longer build --with-libsystemd.  Our replacement carries the
real soname but only the sd_notify() symbols, so in the test root it
shadowed the libsystemd the host's libdbus-1 wants and dbus-daemon
died on a missing sd_is_socket.  Nothing under test needs the shared
library: serv is the only consumer and it compiles sd-daemon.c
straight in, which it now does regardless of the flag so notify.sh
keeps testing notify:systemd either way.

Staged from the host by lib/sysroot.mk like any other binary, and
skipped when the host has neither program.

Signed-off-by: Joachim Wiberg <troglobit@gmail.com>
2026-08-13 10:15:19 +02:00

62 lines
2.5 KiB
Bash
Executable File

#!/bin/sh
# Finit against a real message bus.
#
# Every other dbus-*.sh test drives libink's own client, so the wire
# format is only ever checked against the implementation that produced
# it. Here the dbus plugin brings up a real dbus-daemon, Finit finds
# it and claims org.finit, and then dbus-send talks to Finit: a client
# that shares no code with us.
#
# It also covers the only path the brokerless bus cannot reach, where
# one connection carries every caller and Finit has to ask the broker
# who sent each privileged call.
#
# Skipped when the host has no dbus-daemon or dbus-send to stage.
set -eu
TEST_DIR=$(dirname "$0")
# shellcheck source=/dev/null
. "$TEST_DIR/lib/setup.sh"
# Staged by lib/sysroot.mk from the host, when it has them.
for prog in dbus-daemon dbus-send; do
texec sh -c "command -v $prog >/dev/null" \
|| skip "no $prog in the test root, need it on the host"
done
say 'The dbus plugin started a system bus'
retry 'assert_file_exists /var/run/dbus/system_bus_socket'
say 'Finit claims org.finit on the system bus'
retry "texec dbus-send --system --print-reply --dest=org.freedesktop.DBus \
/org/freedesktop/DBus org.freedesktop.DBus.GetNameOwner string:org.finit" 60 0.5
say 'A read-only method answers through the broker'
list=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.finit.Manager1.ListServices)
assert "ListServices returned the dbus service" \
"$(printf '%s' "$list" | grep -c '"dbus"')" -ge 1
say 'Properties.Get answers through the broker'
rl=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.freedesktop.DBus.Properties.Get \
string:org.finit.Manager1 string:Runlevel)
assert "Runlevel property is 2" "$(printf '%s' "$rl" | grep -c '"2"')" -eq 1
# The point of the exercise: a privileged call over the broker means
# Finit parks it, asks the driver who the sender is, and dispatches on
# the answer. Root is allowed, so reaching NoSuchService proves the
# whole round trip worked rather than a blanket denial. The repeat
# call goes the same way, only answered from the sender cache.
for pass in first repeat; do
say "A privileged method resolves the caller, $pass call"
priv=$(texec dbus-send --system --print-reply --dest=org.finit \
/org/finit/manager org.finit.Manager1.Restart string:nosuchservice 2>&1 || true)
case "$priv" in
*NoSuchService*) assert "Caller identified on the $pass call" 0 -eq 0 ;;
*) fail "Unexpected reply to the $pass privileged call: $priv" ;;
esac
done