diff --git a/control-plane-operator/controllers/hostedcontrolplane/pki/kas.go b/control-plane-operator/controllers/hostedcontrolplane/pki/kas.go index 2455d449ed94..1995c7b9b65f 100644 --- a/control-plane-operator/controllers/hostedcontrolplane/pki/kas.go +++ b/control-plane-operator/controllers/hostedcontrolplane/pki/kas.go @@ -2,7 +2,6 @@ package pki import ( "fmt" - "net" corev1 "k8s.io/api/core/v1" "k8s.io/client-go/tools/clientcmd" @@ -14,6 +13,7 @@ import ( "github.com/openshift/hypershift/control-plane-operator/controllers/hostedcontrolplane/manifests" "github.com/openshift/hypershift/support/certs" "github.com/openshift/hypershift/support/config" + supportpki "github.com/openshift/hypershift/support/pki" "github.com/openshift/hypershift/support/util" utilsnet "k8s.io/utils/net" ) @@ -25,43 +25,9 @@ const ( ) func ReconcileKASServerCertSecret(secret, ca *corev1.Secret, ownerRef config.OwnerRef, externalAPIAddress, internalAPIAddress string, serviceCIDRs []string, nodeInternalAPIServerIP string) error { - svc := manifests.KubeAPIServerService(secret.Namespace) - svcAddresses := make([]string, 0) - - for _, serviceCIDR := range serviceCIDRs { - serviceIP, err := util.FirstUsableIP(serviceCIDR) - if err != nil { - return fmt.Errorf("cannot get the first usable IP from CIDR %s: %w", serviceIP, err) - } - svcAddresses = append(svcAddresses, serviceIP) - } - - dnsNames := []string{ - "localhost", - "kubernetes", - "kubernetes.default", - "kubernetes.default.svc", - "kubernetes.default.svc.cluster.local", - svc.Name, - fmt.Sprintf("%s.%s.svc", svc.Name, svc.Namespace), - fmt.Sprintf("%s.%s.svc.cluster.local", svc.Name, svc.Namespace), - } - apiServerIPs := []string{ - "127.0.0.1", - "0:0:0:0:0:0:0:1", - } - apiServerIPs = append(apiServerIPs, svcAddresses...) - apiServerIPs = append(apiServerIPs, nodeInternalAPIServerIP) - - if isNumericIP(externalAPIAddress) { - apiServerIPs = append(apiServerIPs, externalAPIAddress) - } else { - dnsNames = append(dnsNames, externalAPIAddress) - } - if isNumericIP(internalAPIAddress) { - apiServerIPs = append(apiServerIPs, internalAPIAddress) - } else { - dnsNames = append(dnsNames, internalAPIAddress) + dnsNames, apiServerIPs, err := supportpki.GetKASServerCertificatesSANs(externalAPIAddress, internalAPIAddress, serviceCIDRs, nodeInternalAPIServerIP, secret.Namespace) + if err != nil { + return fmt.Errorf("failed to get KAS server certificates SANs: %w", err) } return reconcileSignedCertWithAddresses(secret, ca, ownerRef, "kubernetes", []string{"kubernetes"}, X509UsageServerAuth, dnsNames, apiServerIPs) } @@ -99,10 +65,6 @@ func ReconcileServiceAccountKubeconfig(secret, csrSigner *corev1.Secret, ca *cor return ReconcileKubeConfig(secret, secret, ca, svcURL, "", manifests.KubeconfigScopeLocal, config.OwnerRef{}) } -func isNumericIP(s string) bool { - return net.ParseIP(s) != nil -} - func ReconcileKubeConfig(secret, cert *corev1.Secret, ca *corev1.ConfigMap, url string, key string, scope manifests.KubeconfigScope, ownerRef config.OwnerRef) error { ownerRef.ApplyTo(secret) caPEM := ca.Data[certs.CASignerCertMapKey] diff --git a/control-plane-operator/controllers/hostedcontrolplane/pki/konnectivity.go b/control-plane-operator/controllers/hostedcontrolplane/pki/konnectivity.go index e6e76196a63f..37a8d091fa2b 100644 --- a/control-plane-operator/controllers/hostedcontrolplane/pki/konnectivity.go +++ b/control-plane-operator/controllers/hostedcontrolplane/pki/konnectivity.go @@ -4,6 +4,8 @@ import ( "fmt" "github.com/openshift/hypershift/support/config" + supportpki "github.com/openshift/hypershift/support/pki" + corev1 "k8s.io/api/core/v1" ) @@ -31,7 +33,7 @@ func ReconcileKonnectivityClusterSecret(secret, ca *corev1.Secret, ownerRef conf fmt.Sprintf("konnectivity-server.%s.svc.cluster.local", secret.Namespace), } ips := []string{} - if isNumericIP(externalKconnectivityAddress) { + if supportpki.IsNumericIP(externalKconnectivityAddress) { ips = append(ips, externalKconnectivityAddress) } else { dnsNames = append(dnsNames, externalKconnectivityAddress) diff --git a/go.mod b/go.mod index 199b661ffc5e..b56e77ed0f04 100644 --- a/go.mod +++ b/go.mod @@ -66,6 +66,7 @@ require ( go.etcd.io/etcd/client/v3 v3.5.13 go.etcd.io/etcd/server/v3 v3.5.13 go.etcd.io/etcd/tests/v3 v3.5.13 + go.uber.org/mock v0.4.0 go.uber.org/zap v1.27.0 golang.org/x/crypto v0.32.0 golang.org/x/net v0.33.0 diff --git a/go.sum b/go.sum index 882f5bd5402a..d2e8ece21f17 100644 --- a/go.sum +++ b/go.sum @@ -645,6 +645,8 @@ go.starlark.net v0.0.0-20231101134539-556fd59b42f6/go.mod h1:LcLNIzVOMp4oV+uusnp go.uber.org/atomic v1.4.0/go.mod h1:gD2HeocX3+yG+ygLZcrzQJaqmWj9AIm7n08wl/qW/PE= go.uber.org/goleak v1.3.0 h1:2K3zAYmnTNqV73imy9J1T3WC+gmCePx2hEGkimedGto= go.uber.org/goleak v1.3.0/go.mod h1:CoHD4mav9JJNrW/WLlf7HGZPjdw8EucARQHekz1X6bE= +go.uber.org/mock v0.4.0 h1:VcM4ZOtdbR4f6VXfiOpwpVJDL6lCReaZ6mw31wqh7KU= +go.uber.org/mock v0.4.0/go.mod h1:a6FSlNadKUHUa9IP5Vyt1zh4fC7uAwxMutEAscFbkZc= go.uber.org/multierr v1.1.0/go.mod h1:wR5kodmAFQ0UK8QlbwjlSNy0Z68gJhDJUG5sjR94q/0= go.uber.org/multierr v1.11.0 h1:blXXJkSxSSfBVBlC76pxqeO+LN3aDfLQo+309xJstO0= go.uber.org/multierr v1.11.0/go.mod h1:20+QtiLqy0Nd6FdQB9TLXag12DsQkrbs3htMFfDN80Y= diff --git a/hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go b/hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go index a43394c9a244..e4c270c305f6 100644 --- a/hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go +++ b/hypershift-operator/controllers/hostedcluster/hostedcluster_controller.go @@ -86,6 +86,7 @@ import ( "github.com/openshift/hypershift/hypershift-operator/controllers/hostedcluster/internal/platform" platformaws "github.com/openshift/hypershift/hypershift-operator/controllers/hostedcluster/internal/platform/aws" hcmetrics "github.com/openshift/hypershift/hypershift-operator/controllers/hostedcluster/metrics" + "github.com/openshift/hypershift/hypershift-operator/controllers/hostedcluster/validations" "github.com/openshift/hypershift/hypershift-operator/controllers/manifests" "github.com/openshift/hypershift/hypershift-operator/controllers/manifests/clusterapi" "github.com/openshift/hypershift/hypershift-operator/controllers/manifests/controlplaneoperator" @@ -3988,6 +3989,10 @@ func (r *HostedClusterReconciler) validateConfigAndClusterCapabilities(ctx conte errs = append(errs, err...) } + if err := r.validateOCPConfigurations(ctx, hc, r.Client); err != nil { + errs = append(errs, err) + } + return utilerrors.NewAggregate(errs) } @@ -4327,6 +4332,20 @@ func (r *HostedClusterReconciler) validateNetworks(hc *hyperv1.HostedCluster) er return errs.ToAggregate() } +// validateOCPConfigurations validates OpenShift-specific configurations for a HostedCluster. +// It's worth to abstract this validation to a separate funtion per API to have them organized. +// Currently validates: +// - API Server configuration +// +// TODO: Add validation for other OpenShift components (e.g. OAuth, Ingress, etc.) +// Jira: https://issues.redhat.com/browse/CNTRLPLANE-382 +func (r *HostedClusterReconciler) validateOCPConfigurations(ctx context.Context, hc *hyperv1.HostedCluster, client client.Client) error { + var errs field.ErrorList + errs = append(errs, validations.ValidateOCPAPIServerSANs(ctx, hc, client)...) + + return errs.ToAggregate() +} + // findAdvertiseAddress function returns a string and an error indicating the AdvertiseAddress for the hostedcluster. // if the advertise address is properly set, it will return that value and nil, otherwise will return an error. // if the advertise address is not set, it will return the default one based on the network primary stack. diff --git a/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver.go b/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver.go new file mode 100644 index 000000000000..0120b0d96eca --- /dev/null +++ b/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver.go @@ -0,0 +1,155 @@ +package validations + +import ( + "context" + "encoding/pem" + "fmt" + "slices" + + hyperv1 "github.com/openshift/hypershift/api/hypershift/v1beta1" + "github.com/openshift/hypershift/hypershift-operator/controllers/manifests" + supportpki "github.com/openshift/hypershift/support/pki" + + corev1 "k8s.io/api/core/v1" + apierrors "k8s.io/apimachinery/pkg/api/errors" + "k8s.io/apimachinery/pkg/types" + "k8s.io/apimachinery/pkg/util/validation/field" + + "sigs.k8s.io/controller-runtime/pkg/client" +) + +const ( + KASServerPrivateCertSecretName = "kas-server-private-crt" + KASServerCertSecretName = "kas-server-crt" +) + +func ValidateOCPAPIServerSANs(ctx context.Context, hc *hyperv1.HostedCluster, client client.Client) field.ErrorList { + var ( + errs field.ErrorList + err error + entryCertDNSNames = make([]string, 0) + entryCertIPs = make([]string, 0) + kasNames = make([]string, 0) + kasIPs = make([]string, 0) + ) + + // At this point, maybe the HCP is not there yet + if hc.Spec.Configuration != nil && hc.Spec.Configuration.APIServer != nil && hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates != nil { + for _, cert := range hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates { + entryCertDNSNames = append(entryCertDNSNames, cert.Names...) + if len(cert.ServingCertificate.Name) > 0 { + secret := &corev1.Secret{} + err = client.Get(ctx, types.NamespacedName{Namespace: hc.Namespace, Name: cert.ServingCertificate.Name}, secret) + if err != nil { + errs = append(errs, field.Invalid(field.NewPath("NamedCertificates get secret"), cert.ServingCertificate.Name, err.Error())) + return errs + } + entryCertDNSNames, entryCertIPs, err = getSANsFromSecretCert(entryCertDNSNames, entryCertIPs, secret) + if err != nil { + errs = append(errs, field.Invalid(field.NewPath("KAS TLS private cert decrypt"), KASServerPrivateCertSecretName, err.Error())) + return errs + } + } + } + + kasNames, kasIPs, err = supportpki.GetKASServerCertificatesSANs("", fmt.Sprintf("api.%s.hypershift.local", hc.Name), []string{}, "", hc.Namespace) + if err != nil { + errs = append(errs, field.Invalid(field.NewPath("Hypershift KAS SANs"), entryCertDNSNames, err.Error())) + } + + if err := checkConflictingSANs(entryCertDNSNames, kasNames, "DNS names"); err != nil { + errs = append(errs, field.Invalid(field.NewPath("conflicting entries with KAS SANs"), entryCertDNSNames, err.Error())) + return errs + } + + if err := checkConflictingSANs(entryCertIPs, kasIPs, "IP addresses"); err != nil { + errs = append(errs, field.Invalid(field.NewPath("conflicting entries with KAS SANs"), entryCertIPs, err.Error())) + return errs + } + } + + hcpNamespace := manifests.HostedControlPlaneNamespace(hc.Namespace, hc.Name) + + // Check the KAS TLS private secret + kasServerPrivateSecret := &corev1.Secret{} + err = client.Get(ctx, types.NamespacedName{Namespace: hcpNamespace, Name: KASServerPrivateCertSecretName}, kasServerPrivateSecret) + if err != nil { + if !apierrors.IsNotFound(err) { + errs = append(errs, field.Invalid(field.NewPath("KAS TLS secret"), "error grabbing KAS TLS secret", err.Error())) + } + // return early, we can assume that the KAS is not there yet + return errs + } + kasNames, kasIPs, err = getSANsFromSecretCert(kasNames, kasIPs, kasServerPrivateSecret) + if err != nil { + errs = append(errs, field.Invalid(field.NewPath("KAS TLS cert decrypt"), KASServerPrivateCertSecretName, err.Error())) + } + + // Check the KAS TLS certificate secret + kasServerCertSecret := &corev1.Secret{} + err = client.Get(ctx, types.NamespacedName{Namespace: hcpNamespace, Name: KASServerCertSecretName}, kasServerCertSecret) + if err != nil { + if !apierrors.IsNotFound(err) { + errs = append(errs, field.Invalid(field.NewPath("KAS TLS secret"), "error grabbing KAS TLS secret", err.Error())) + } + // return early, we can assume that the KAS is not there yet + return errs + } + + kasNames, kasIPs, err = getSANsFromSecretCert(kasNames, kasIPs, kasServerCertSecret) + if err != nil { + errs = append(errs, field.Invalid(field.NewPath("KAS TLS cert decrypt"), KASServerCertSecretName, err.Error())) + } + + if err := checkConflictingSANs(entryCertDNSNames, kasNames, "DNS names"); err != nil { + errs = append(errs, field.Invalid(field.NewPath("custom serving cert"), entryCertDNSNames, err.Error())) + return errs + } + + if err := checkConflictingSANs(entryCertIPs, kasIPs, "IP addresses"); err != nil { + errs = append(errs, field.Invalid(field.NewPath("custom serving cert"), entryCertIPs, err.Error())) + return errs + } + + return errs +} + +func getSANsFromSecretCert(entryCertDNSNames []string, entryCertIPs []string, secretCert *corev1.Secret) ([]string, []string, error) { + if secretCert == nil || secretCert.Data == nil || len(secretCert.Data["tls.crt"]) == 0 { + return nil, nil, fmt.Errorf("TLS secret or certificate entries are empty") + } + + // Try to parse the certificate as PEM + block, _ := pem.Decode(secretCert.Data["tls.crt"]) + if block == nil { + return nil, nil, fmt.Errorf("failed to decode PEM block from certificate") + } + + certSANsDNS, certSANsIPs, err := supportpki.GetSANsFromCertificate(block.Bytes) + if err != nil { + return nil, nil, fmt.Errorf("error decrypting TLS certificate: %w", err) + } + + tempEntryCertDNSNames := appendEntriesIfNotExists(entryCertDNSNames, certSANsDNS) + tempEntryCertIPs := appendEntriesIfNotExists(entryCertIPs, certSANsIPs) + + return tempEntryCertDNSNames, tempEntryCertIPs, nil +} + +func appendEntriesIfNotExists(slice []string, entries []string) []string { + for _, entry := range entries { + if !slices.Contains(slice, entry) { + slice = append(slice, entry) + } + } + return slice +} + +func checkConflictingSANs(customEntries []string, kasSANEntries []string, entryType string) error { + for _, customEntry := range customEntries { + if slices.Contains(kasSANEntries, customEntry) { + return fmt.Errorf("conflicting %s found in KAS SANs. Configuration is invalid", entryType) + } + } + return nil +} diff --git a/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver_test.go b/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver_test.go new file mode 100644 index 000000000000..d67052fccd51 --- /dev/null +++ b/hypershift-operator/controllers/hostedcluster/validations/ocpapiserver_test.go @@ -0,0 +1,417 @@ +package validations + +import ( + "context" + "fmt" + "testing" + "time" + + . "github.com/onsi/gomega" + + hyperv1 "github.com/openshift/hypershift/api/hypershift/v1beta1" + "github.com/openshift/hypershift/test/util" + + configv1 "github.com/openshift/api/config/v1" + + corev1 "k8s.io/api/core/v1" + metav1 "k8s.io/apimachinery/pkg/apis/meta/v1" + "k8s.io/apimachinery/pkg/runtime" + "k8s.io/apimachinery/pkg/types" + "k8s.io/apimachinery/pkg/util/validation/field" + + "sigs.k8s.io/controller-runtime/pkg/client" + "sigs.k8s.io/controller-runtime/pkg/client/fake" +) + +const ( + customServingCertSecretName = "custom-serving-cert" +) + +func TestValidateOCPAPIServerSANs(t *testing.T) { + scheme := runtime.NewScheme() + _ = corev1.AddToScheme(scheme) + _ = hyperv1.AddToScheme(scheme) + _ = configv1.AddToScheme(scheme) + + kasServerCertSecret := sampleKASServerCertSecret() + kasServerPrivateCertSecret := sampleKASServerPrivateCertSecret() + + // Get a sample HostedCluster + hc := sampleHostedCluster() + + tests := []struct { + name string + customCertSecret *corev1.Secret + secrets []client.Object + namedCertificates []configv1.APIServerNamedServingCert + expectedErrors field.ErrorList + dnsNames []string + ipAddresses []string + }{ + { + name: "custom serving cert, hcp deployed, valid configuration with no conflicts", + customCertSecret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: customServingCertSecretName, + Namespace: "clusters", + }, + }, + dnsNames: []string{"test.example.com"}, + ipAddresses: []string{"192.168.1.1"}, + secrets: []client.Object{ + kasServerCertSecret, + kasServerPrivateCertSecret, + }, + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: nil, + }, + { + name: "custom serving cert, hcp not deployed, valid configuration with no conflicts", + customCertSecret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: customServingCertSecretName, + Namespace: "clusters", + }, + }, + dnsNames: []string{"test.example.com"}, + secrets: []client.Object{}, + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: nil, + }, + { + name: "invalid certificate format", + customCertSecret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: customServingCertSecretName, + Namespace: "clusters", + }, + Data: map[string][]byte{ + "tls.crt": []byte("invalid certificate"), + }, + }, + secrets: []client.Object{}, + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: field.ErrorList{ + field.Invalid(field.NewPath("KAS TLS private cert decrypt"), KASServerPrivateCertSecretName, "failed to decode PEM block from certificate"), + }, + }, + { + name: "missing secret", + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: field.ErrorList{ + field.Invalid(field.NewPath("NamedCertificates get secret"), "custom-serving-cert", "secrets \"custom-serving-cert\" not found"), + }, + }, + { + name: "no custom serving cert, hcp not deployed, valid configuration with no conflicts", + secrets: []client.Object{}, + expectedErrors: nil, + }, + { + name: "conflicting SANs with KAS", + + customCertSecret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: customServingCertSecretName, + Namespace: "clusters", + }, + }, + dnsNames: []string{"test-conflicting-kas-san.example.com"}, + secrets: []client.Object{ + kasServerCertSecret, + kasServerPrivateCertSecret, + }, + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test-conflicting-kas-san.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: field.ErrorList{ + field.Invalid(field.NewPath("custom serving cert"), []string{"test-conflicting-kas-san.example.com"}, "conflicting DNS names found in KAS SANs. Configuration is invalid"), + }, + }, + { + name: "invalid certificate data", + customCertSecret: &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: customServingCertSecretName, + Namespace: "clusters", + }, + Data: map[string][]byte{ + "tls.crt": []byte("invalid certificate data"), + }, + }, + secrets: []client.Object{ + kasServerCertSecret, + kasServerPrivateCertSecret, + }, + namedCertificates: []configv1.APIServerNamedServingCert{ + { + Names: []string{"test.example.com"}, + ServingCertificate: configv1.SecretNameReference{Name: customServingCertSecretName}, + }, + }, + expectedErrors: field.ErrorList{ + field.Invalid(field.NewPath("KAS TLS private cert decrypt"), KASServerPrivateCertSecretName, "failed to decode PEM block from certificate"), + }, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + var ( + pemCert []byte + pemKey []byte + err error + g = NewWithT(t) + ) + + if len(tt.namedCertificates) > 0 && (tt.customCertSecret != nil && tt.customCertSecret.Data == nil) { + // Generate a test certificate + pemCert, pemKey, err = util.GenerateTestCertificate(context.Background(), tt.dnsNames, tt.ipAddresses, 24*time.Hour) + g.Expect(err).NotTo(HaveOccurred()) + g.Expect(pemCert).NotTo(BeNil()) + } + + // Initialize secrets with proper data + objects := make([]client.Object, 0) + if tt.customCertSecret != nil { + if tt.customCertSecret.Data == nil { + tt.customCertSecret.Data = make(map[string][]byte) + tt.customCertSecret.Data["tls.crt"] = pemCert + tt.customCertSecret.Data["tls.key"] = pemKey + } + objects = append(objects, tt.customCertSecret) + } + + // Add KAS secrets if they are in the test case + if len(tt.secrets) > 0 { + objects = append(objects, tt.secrets...) + } + + if len(tt.namedCertificates) > 0 { + hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates = tt.namedCertificates + objects = append(objects, hc) + } + + // Create a new client with the scheme and objects + fakeClient := fake.NewClientBuilder(). + WithScheme(scheme). + WithObjects(objects...). + Build() + + // Verify that the secrets were added correctly + for _, object := range objects { + switch object.(type) { + case *corev1.Secret: + var foundSecret corev1.Secret + err := fakeClient.Get(context.Background(), types.NamespacedName{ + Name: object.GetName(), + Namespace: object.GetNamespace(), + }, &foundSecret) + g.Expect(err).ToNot(HaveOccurred(), "failed to get secret %s/%s", object.GetNamespace(), object.GetName()) + g.Expect(foundSecret.Data).ToNot(BeNil(), "secret data should not be nil") + g.Expect(foundSecret.Data["tls.crt"]).ToNot(BeEmpty(), "certificate data should not be empty") + } + } + + if hc.Spec.Configuration == nil { + hc.Spec.Configuration = &hyperv1.ClusterConfiguration{} + } + if hc.Spec.Configuration.APIServer == nil { + hc.Spec.Configuration.APIServer = &configv1.APIServerSpec{} + } + if hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates == nil { + hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates = []configv1.APIServerNamedServingCert{} + } + hc.Spec.Configuration.APIServer.ServingCerts.NamedCertificates = tt.namedCertificates + errs := ValidateOCPAPIServerSANs(context.Background(), hc, fakeClient) + g.Expect(errs).To(Equal(tt.expectedErrors)) + }) + } +} + +func TestAppendEntriesIfNotExists(t *testing.T) { + tests := []struct { + name string + slice []string + entries []string + expected []string + }{ + { + name: "empty slice and entries", + slice: []string{}, + entries: []string{}, + expected: []string{}, + }, + { + name: "add new entries", + slice: []string{"a", "b"}, + entries: []string{"c", "d"}, + expected: []string{"a", "b", "c", "d"}, + }, + { + name: "add existing and new entries", + slice: []string{"a", "b"}, + entries: []string{"b", "c"}, + expected: []string{"a", "b", "c"}, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + g := NewWithT(t) + result := appendEntriesIfNotExists(tt.slice, tt.entries) + g.Expect(result).To(Equal(tt.expected)) + }) + } +} + +func TestCheckConflictingSANs(t *testing.T) { + tests := []struct { + name string + customEntries []string + kasSANEntries []string + entryType string + expectError bool + }{ + { + name: "no conflicts", + customEntries: []string{"a", "b"}, + kasSANEntries: []string{"c", "d"}, + entryType: "DNS names", + expectError: false, + }, + { + name: "has conflicts", + customEntries: []string{"a", "b"}, + kasSANEntries: []string{"b", "c"}, + entryType: "DNS names", + expectError: true, + }, + { + name: "empty entries", + customEntries: []string{}, + kasSANEntries: []string{}, + entryType: "DNS names", + expectError: false, + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + g := NewWithT(t) + err := checkConflictingSANs(tt.customEntries, tt.kasSANEntries, tt.entryType) + if tt.expectError { + g.Expect(err).To(HaveOccurred()) + g.Expect(err.Error()).To(ContainSubstring("conflicting")) + } else { + g.Expect(err).ToNot(HaveOccurred()) + } + }) + } +} + +func sampleKASServerCertSecret() *corev1.Secret { + pemCert, pemKey, err := util.GenerateTestCertificate( + context.Background(), + []string{ + "kube-apiserver", + "kube-apiserver.clusters-jparrill-hosted.svc", + "kube-apiserver.clusters-jparrill-hosted.svc.cluster.local", + "test-conflicting-kas-san.example.com", + }, + []string{}, + 24*time.Hour, + ) + if err != nil { + panic(fmt.Sprintf("failed to generate KAS server certificate: %v", err)) + } + + return &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: KASServerCertSecretName, + Namespace: "clusters-test", + }, + Data: map[string][]byte{ + "tls.crt": pemCert, + "tls.key": pemKey, + }, + Type: corev1.SecretTypeTLS, + } +} + +func sampleKASServerPrivateCertSecret() *corev1.Secret { + pemCert, pemKey, err := util.GenerateTestCertificate( + context.Background(), + []string{ + "localhost", + "kubernetes", + "kubernetes.default", + "kubernetes.default.svc", + "kubernetes.default.svc.cluster.local", + "openshift", + "openshift.default", + "openshift.default.svc", + "openshift.default.svc.cluster.local", + }, + []string{"127.0.0.1", "::1"}, + 24*time.Hour, + ) + if err != nil { + panic(fmt.Sprintf("failed to generate KAS private certificate: %v", err)) + } + + // Create a PEM block for the certificate + + return &corev1.Secret{ + ObjectMeta: metav1.ObjectMeta{ + Name: KASServerPrivateCertSecretName, + Namespace: "clusters-test", + }, + Data: map[string][]byte{ + "tls.crt": pemCert, + "tls.key": pemKey, + }, + Type: corev1.SecretTypeTLS, + } +} + +func sampleHostedCluster() *hyperv1.HostedCluster { + return &hyperv1.HostedCluster{ + ObjectMeta: metav1.ObjectMeta{ + Name: "test", + Namespace: "clusters", + }, + Spec: hyperv1.HostedClusterSpec{ + Configuration: &hyperv1.ClusterConfiguration{ + APIServer: &configv1.APIServerSpec{ + ServingCerts: configv1.APIServerServingCerts{ + NamedCertificates: []configv1.APIServerNamedServingCert{}, + }, + }, + }, + }, + } +} diff --git a/support/pki/kas.go b/support/pki/kas.go new file mode 100644 index 000000000000..a4dd7e3c90ed --- /dev/null +++ b/support/pki/kas.go @@ -0,0 +1,78 @@ +package pki + +import ( + "crypto/x509" + "fmt" + "net" + + "github.com/openshift/hypershift/control-plane-operator/controllers/hostedcontrolplane/manifests" + "github.com/openshift/hypershift/support/util" +) + +func GetKASServerCertificatesSANs(externalAPIAddress, internalAPIAddress string, serviceCIDRs []string, nodeInternalAPIServerIP string, namespace string) ([]string, []string, error) { + svcAddresses := make([]string, 0) + svc := manifests.KubeAPIServerService(namespace) + + for _, serviceCIDR := range serviceCIDRs { + serviceIP, err := util.FirstUsableIP(serviceCIDR) + if err != nil { + return nil, nil, fmt.Errorf("cannot get the first usable IP from CIDR %s: %w", serviceIP, err) + } + svcAddresses = append(svcAddresses, serviceIP) + } + + dnsNames := []string{ + "localhost", + "kubernetes", + "kubernetes.default", + "kubernetes.default.svc", + "kubernetes.default.svc.cluster.local", + svc.Name, + // This is needed to configure Openshift Auth Provider that talks to openshift.default.svc + "openshift", + "openshift.default", + "openshift.default.svc", + "openshift.default.svc.cluster.local", + } + apiServerIPs := []string{ + "127.0.0.1", + "0:0:0:0:0:0:0:1", + } + apiServerIPs = append(apiServerIPs, svcAddresses...) + apiServerIPs = append(apiServerIPs, nodeInternalAPIServerIP) + + if IsNumericIP(externalAPIAddress) { + apiServerIPs = append(apiServerIPs, externalAPIAddress) + } else { + dnsNames = append(dnsNames, externalAPIAddress) + } + if IsNumericIP(internalAPIAddress) { + apiServerIPs = append(apiServerIPs, internalAPIAddress) + } else { + dnsNames = append(dnsNames, internalAPIAddress) + } + + return dnsNames, apiServerIPs, nil +} + +func IsNumericIP(s string) bool { + return net.ParseIP(s) != nil +} + +// GetSANsFromCertificate returns the SANs from a certificate as separate DNS names and IP addresses +func GetSANsFromCertificate(cert []byte) ([]string, []string, error) { + parsedCert, err := x509.ParseCertificate(cert) + if err != nil { + return nil, nil, fmt.Errorf("failed to parse certificate: %w", err) + } + + dnsNames := make([]string, len(parsedCert.DNSNames)) + copy(dnsNames, parsedCert.DNSNames) + + ipAddresses := make([]string, 0, len(parsedCert.IPAddresses)) + for _, ip := range parsedCert.IPAddresses { + ipAddresses = append(ipAddresses, ip.String()) + } + + return dnsNames, ipAddresses, nil +} diff --git a/support/pki/kas_test.go b/support/pki/kas_test.go new file mode 100644 index 000000000000..163e500e11a2 --- /dev/null +++ b/support/pki/kas_test.go @@ -0,0 +1,88 @@ +package pki + +import ( + "crypto/rand" + "crypto/rsa" + "crypto/x509" + "crypto/x509/pkix" + "math/big" + "net" + "testing" + "time" + + . "github.com/onsi/gomega" +) + +func TestGetSANsFromCertificate(t *testing.T) { + g := NewWithT(t) + // Create a test certificate with known SANs + template := &x509.Certificate{ + SerialNumber: big.NewInt(1), + Subject: pkix.Name{ + Organization: []string{"Test Org"}, + }, + NotBefore: time.Now(), + NotAfter: time.Now().Add(time.Hour * 24), + KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + BasicConstraintsValid: true, + DNSNames: []string{ + "test.example.com", + "*.test.example.com", + }, + IPAddresses: []net.IP{ + net.ParseIP("192.168.1.1"), + net.ParseIP("2001:db8::1"), + }, + } + + // Generate a private key + privateKey, err := rsa.GenerateKey(rand.Reader, 2048) + g.Expect(err).ToNot(HaveOccurred()) + + // Create the certificate + certDER, err := x509.CreateCertificate(rand.Reader, template, template, &privateKey.PublicKey, privateKey) + g.Expect(err).ToNot(HaveOccurred()) + + // Test cases + testCases := []struct { + name string + cert []byte + expectedDNS []string + expectedIPs []string + expectedError bool + }{ + { + name: "valid certificate", + cert: certDER, + expectedDNS: []string{"test.example.com", "*.test.example.com"}, + expectedIPs: []string{"192.168.1.1", "2001:db8::1"}, + }, + { + name: "invalid certificate", + cert: []byte("invalid certificate"), + expectedError: true, + }, + { + name: "empty certificate", + cert: []byte{}, + expectedError: true, + }, + } + + for _, tc := range testCases { + t.Run(tc.name, func(t *testing.T) { + g := NewWithT(t) + dnsNames, ipAddresses, err := GetSANsFromCertificate(tc.cert) + + if tc.expectedError { + g.Expect(err).To(HaveOccurred()) + return + } + + g.Expect(err).ToNot(HaveOccurred()) + g.Expect(dnsNames).To(ConsistOf(tc.expectedDNS), "DNS names don't match") + g.Expect(ipAddresses).To(ConsistOf(tc.expectedIPs), "IP addresses don't match") + }) + } +} diff --git a/support/releaseinfo/providerwithregistryoverrides_mock.go b/support/releaseinfo/providerwithregistryoverrides_mock.go new file mode 100644 index 000000000000..9520179e9564 --- /dev/null +++ b/support/releaseinfo/providerwithregistryoverrides_mock.go @@ -0,0 +1,190 @@ +// Code generated by MockGen. DO NOT EDIT. +// Source: releaseinfo.go +// +// Generated by this command: +// +// mockgen -source=releaseinfo.go -package=releaseinfo -destination=providerwithregistryoverrides_mock.go +// + +// Package releaseinfo is a generated GoMock package. +package releaseinfo + +import ( + context "context" + reflect "reflect" + + gomock "go.uber.org/mock/gomock" +) + +// MockProvider is a mock of Provider interface. +type MockProvider struct { + ctrl *gomock.Controller + recorder *MockProviderMockRecorder + isgomock struct{} +} + +// MockProviderMockRecorder is the mock recorder for MockProvider. +type MockProviderMockRecorder struct { + mock *MockProvider +} + +// NewMockProvider creates a new mock instance. +func NewMockProvider(ctrl *gomock.Controller) *MockProvider { + mock := &MockProvider{ctrl: ctrl} + mock.recorder = &MockProviderMockRecorder{mock} + return mock +} + +// EXPECT returns an object that allows the caller to indicate expected use. +func (m *MockProvider) EXPECT() *MockProviderMockRecorder { + return m.recorder +} + +// Lookup mocks base method. +func (m *MockProvider) Lookup(ctx context.Context, image string, pullSecret []byte) (*ReleaseImage, error) { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "Lookup", ctx, image, pullSecret) + ret0, _ := ret[0].(*ReleaseImage) + ret1, _ := ret[1].(error) + return ret0, ret1 +} + +// Lookup indicates an expected call of Lookup. +func (mr *MockProviderMockRecorder) Lookup(ctx, image, pullSecret any) *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "Lookup", reflect.TypeOf((*MockProvider)(nil).Lookup), ctx, image, pullSecret) +} + +// MockProviderWithRegistryOverrides is a mock of ProviderWithRegistryOverrides interface. +type MockProviderWithRegistryOverrides struct { + ctrl *gomock.Controller + recorder *MockProviderWithRegistryOverridesMockRecorder + isgomock struct{} +} + +// MockProviderWithRegistryOverridesMockRecorder is the mock recorder for MockProviderWithRegistryOverrides. +type MockProviderWithRegistryOverridesMockRecorder struct { + mock *MockProviderWithRegistryOverrides +} + +// NewMockProviderWithRegistryOverrides creates a new mock instance. +func NewMockProviderWithRegistryOverrides(ctrl *gomock.Controller) *MockProviderWithRegistryOverrides { + mock := &MockProviderWithRegistryOverrides{ctrl: ctrl} + mock.recorder = &MockProviderWithRegistryOverridesMockRecorder{mock} + return mock +} + +// EXPECT returns an object that allows the caller to indicate expected use. +func (m *MockProviderWithRegistryOverrides) EXPECT() *MockProviderWithRegistryOverridesMockRecorder { + return m.recorder +} + +// GetRegistryOverrides mocks base method. +func (m *MockProviderWithRegistryOverrides) GetRegistryOverrides() map[string]string { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "GetRegistryOverrides") + ret0, _ := ret[0].(map[string]string) + return ret0 +} + +// GetRegistryOverrides indicates an expected call of GetRegistryOverrides. +func (mr *MockProviderWithRegistryOverridesMockRecorder) GetRegistryOverrides() *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "GetRegistryOverrides", reflect.TypeOf((*MockProviderWithRegistryOverrides)(nil).GetRegistryOverrides)) +} + +// Lookup mocks base method. +func (m *MockProviderWithRegistryOverrides) Lookup(ctx context.Context, image string, pullSecret []byte) (*ReleaseImage, error) { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "Lookup", ctx, image, pullSecret) + ret0, _ := ret[0].(*ReleaseImage) + ret1, _ := ret[1].(error) + return ret0, ret1 +} + +// Lookup indicates an expected call of Lookup. +func (mr *MockProviderWithRegistryOverridesMockRecorder) Lookup(ctx, image, pullSecret any) *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "Lookup", reflect.TypeOf((*MockProviderWithRegistryOverrides)(nil).Lookup), ctx, image, pullSecret) +} + +// MockProviderWithOpenShiftImageRegistryOverrides is a mock of ProviderWithOpenShiftImageRegistryOverrides interface. +type MockProviderWithOpenShiftImageRegistryOverrides struct { + ctrl *gomock.Controller + recorder *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder + isgomock struct{} +} + +// MockProviderWithOpenShiftImageRegistryOverridesMockRecorder is the mock recorder for MockProviderWithOpenShiftImageRegistryOverrides. +type MockProviderWithOpenShiftImageRegistryOverridesMockRecorder struct { + mock *MockProviderWithOpenShiftImageRegistryOverrides +} + +// NewMockProviderWithOpenShiftImageRegistryOverrides creates a new mock instance. +func NewMockProviderWithOpenShiftImageRegistryOverrides(ctrl *gomock.Controller) *MockProviderWithOpenShiftImageRegistryOverrides { + mock := &MockProviderWithOpenShiftImageRegistryOverrides{ctrl: ctrl} + mock.recorder = &MockProviderWithOpenShiftImageRegistryOverridesMockRecorder{mock} + return mock +} + +// EXPECT returns an object that allows the caller to indicate expected use. +func (m *MockProviderWithOpenShiftImageRegistryOverrides) EXPECT() *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder { + return m.recorder +} + +// GetMirroredReleaseImage mocks base method. +func (m *MockProviderWithOpenShiftImageRegistryOverrides) GetMirroredReleaseImage() string { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "GetMirroredReleaseImage") + ret0, _ := ret[0].(string) + return ret0 +} + +// GetMirroredReleaseImage indicates an expected call of GetMirroredReleaseImage. +func (mr *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder) GetMirroredReleaseImage() *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "GetMirroredReleaseImage", reflect.TypeOf((*MockProviderWithOpenShiftImageRegistryOverrides)(nil).GetMirroredReleaseImage)) +} + +// GetOpenShiftImageRegistryOverrides mocks base method. +func (m *MockProviderWithOpenShiftImageRegistryOverrides) GetOpenShiftImageRegistryOverrides() map[string][]string { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "GetOpenShiftImageRegistryOverrides") + ret0, _ := ret[0].(map[string][]string) + return ret0 +} + +// GetOpenShiftImageRegistryOverrides indicates an expected call of GetOpenShiftImageRegistryOverrides. +func (mr *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder) GetOpenShiftImageRegistryOverrides() *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "GetOpenShiftImageRegistryOverrides", reflect.TypeOf((*MockProviderWithOpenShiftImageRegistryOverrides)(nil).GetOpenShiftImageRegistryOverrides)) +} + +// GetRegistryOverrides mocks base method. +func (m *MockProviderWithOpenShiftImageRegistryOverrides) GetRegistryOverrides() map[string]string { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "GetRegistryOverrides") + ret0, _ := ret[0].(map[string]string) + return ret0 +} + +// GetRegistryOverrides indicates an expected call of GetRegistryOverrides. +func (mr *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder) GetRegistryOverrides() *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "GetRegistryOverrides", reflect.TypeOf((*MockProviderWithOpenShiftImageRegistryOverrides)(nil).GetRegistryOverrides)) +} + +// Lookup mocks base method. +func (m *MockProviderWithOpenShiftImageRegistryOverrides) Lookup(ctx context.Context, image string, pullSecret []byte) (*ReleaseImage, error) { + m.ctrl.T.Helper() + ret := m.ctrl.Call(m, "Lookup", ctx, image, pullSecret) + ret0, _ := ret[0].(*ReleaseImage) + ret1, _ := ret[1].(error) + return ret0, ret1 +} + +// Lookup indicates an expected call of Lookup. +func (mr *MockProviderWithOpenShiftImageRegistryOverridesMockRecorder) Lookup(ctx, image, pullSecret any) *gomock.Call { + mr.mock.ctrl.T.Helper() + return mr.mock.ctrl.RecordCallWithMethodType(mr.mock, "Lookup", reflect.TypeOf((*MockProviderWithOpenShiftImageRegistryOverrides)(nil).Lookup), ctx, image, pullSecret) +} diff --git a/test/util/pki.go b/test/util/pki.go new file mode 100644 index 000000000000..ff5a648a8f4c --- /dev/null +++ b/test/util/pki.go @@ -0,0 +1,91 @@ +package util + +import ( + "context" + "crypto/rand" + "crypto/rsa" + "crypto/x509" + "crypto/x509/pkix" + "encoding/pem" + "fmt" + "math/big" + "net" + "time" +) + +// GenerateTestCertificate creates a test certificate with the given DNS names and IP addresses +func GenerateTestCertificate(ctx context.Context, dnsNames []string, ipAddresses []string, duration time.Duration) ([]byte, []byte, error) { + var cn string + + // Generate a private key + if len(dnsNames) == 0 && len(ipAddresses) == 0 { + return nil, nil, fmt.Errorf("no DNS names or IP addresses provided") + } + + // set the common name to the first DNS name or ip address + if len(dnsNames) > 0 { + cn = dnsNames[0] + } else { + cn = ipAddresses[0] + } + + privateKey, err := rsa.GenerateKey(rand.Reader, 2048) + if err != nil { + return nil, nil, err + } + + // Convert IP addresses to net.IP + ips := make([]net.IP, len(ipAddresses)) + for i, ip := range ipAddresses { + ips[i] = net.ParseIP(ip) + } + + // Create certificate template + template := &x509.Certificate{ + SerialNumber: big.NewInt(1), + Subject: pkix.Name{ + Organization: []string{"HostedControlPlanes TestOrg"}, + CommonName: cn, + }, + NotBefore: time.Now(), + NotAfter: time.Now().Add(duration), + KeyUsage: x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature, + ExtKeyUsage: []x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth}, + BasicConstraintsValid: true, + DNSNames: dnsNames, + IPAddresses: ips, + IsCA: true, + MaxPathLen: 0, + MaxPathLenZero: true, + } + + // Create the certificate + certDER, err := x509.CreateCertificate(rand.Reader, template, template, &privateKey.PublicKey, privateKey) + if err != nil { + return nil, nil, fmt.Errorf("failed to create certificate: %w", err) + } + + // Validate the certificate by parsing it + _, err = x509.ParseCertificate(certDER) + if err != nil { + return nil, nil, fmt.Errorf("failed to parse generated certificate: %w", err) + } + + // Convert private key to PEM format + privateKeyPEM := pem.EncodeToMemory(&pem.Block{ + Type: "RSA PRIVATE KEY", + Bytes: x509.MarshalPKCS1PrivateKey(privateKey), + }) + + // Convert certificate to PEM format + certPEM := pem.EncodeToMemory(&pem.Block{ + Type: "CERTIFICATE", + Bytes: certDER, + }) + + // Add newline to both PEM blocks + privateKeyPEM = append(privateKeyPEM, '\n') + certPEM = append(certPEM, '\n') + + return certPEM, privateKeyPEM, nil +} diff --git a/test/util/pki_test.go b/test/util/pki_test.go new file mode 100644 index 000000000000..15b0170d360b --- /dev/null +++ b/test/util/pki_test.go @@ -0,0 +1,137 @@ +package util + +import ( + "context" + "crypto/x509" + "encoding/pem" + "testing" + "time" + + . "github.com/onsi/gomega" + + "sigs.k8s.io/controller-runtime/pkg/log" + + "github.com/go-logr/logr/testr" +) + +func TestGenerateTestCertificate(t *testing.T) { + ctx := log.IntoContext(context.Background(), testr.New(t)) + + testsCases := []struct { + name string + dnsNames []string + ipAddresses []string + duration time.Duration + wantErr bool + expectedCN string + }{ + { + name: "When generating a certificate with DNS names it should succeed", + dnsNames: []string{"example.com", "test.example.com"}, + ipAddresses: []string{"192.168.1.1"}, + duration: 24 * time.Hour, + wantErr: false, + expectedCN: "example.com", + }, + { + name: "When generating a certificate with IP addresses only it should succeed", + dnsNames: []string{}, + ipAddresses: []string{"192.168.1.1", "10.0.0.1"}, + duration: 24 * time.Hour, + wantErr: false, + expectedCN: "192.168.1.1", + }, + { + name: "When generating a certificate with no DNS names or IP addresses it should fail", + dnsNames: []string{}, + ipAddresses: []string{}, + duration: 24 * time.Hour, + wantErr: true, + }, + { + name: "When generating a certificate with invalid IP address it should fail", + dnsNames: []string{}, + ipAddresses: []string{"invalid.ip.address"}, + duration: 24 * time.Hour, + wantErr: true, + }, + { + name: "When generating a certificate with zero duration it should succeed", + dnsNames: []string{"example.com"}, + ipAddresses: []string{"192.168.1.1"}, + duration: 0, + wantErr: false, + expectedCN: "example.com", + }, + } + + for _, tc := range testsCases { + t.Run(tc.name, func(t *testing.T) { + g := NewWithT(t) + certPEM, keyPEM, err := GenerateTestCertificate(ctx, tc.dnsNames, tc.ipAddresses, tc.duration) + + if tc.wantErr { + g.Expect(err).To(HaveOccurred()) + return + } + + g.Expect(err).NotTo(HaveOccurred()) + g.Expect(certPEM).NotTo(BeNil()) + g.Expect(keyPEM).NotTo(BeNil()) + + // Verify PEM blocks have newlines at the end + g.Expect(certPEM[len(certPEM)-1]).To(Equal(byte('\n'))) + g.Expect(keyPEM[len(keyPEM)-1]).To(Equal(byte('\n'))) + + // Parse the certificate to verify its contents + block, _ := pem.Decode(certPEM) + g.Expect(block).NotTo(BeNil()) + g.Expect(block.Type).To(Equal("CERTIFICATE")) + + cert, err := x509.ParseCertificate(block.Bytes) + g.Expect(err).NotTo(HaveOccurred()) + + // Verify CommonName + g.Expect(cert.Subject.CommonName).To(Equal(tc.expectedCN)) + + // Verify DNS names + if len(tc.dnsNames) == 0 { + g.Expect(cert.DNSNames).To(BeEmpty()) + } else { + g.Expect(cert.DNSNames).To(Equal(tc.dnsNames)) + } + + // Verify IP addresses + if len(tc.ipAddresses) > 0 { + g.Expect(cert.IPAddresses).To(HaveLen(len(tc.ipAddresses))) + } + + // Verify certificate is self-signed + g.Expect(cert.Subject.CommonName).To(Equal(cert.Issuer.CommonName)) + g.Expect(cert.Subject.Organization).To(Equal(cert.Issuer.Organization)) + + // Verify certificate is a CA + g.Expect(cert.IsCA).To(BeTrue()) + g.Expect(cert.MaxPathLen).To(Equal(0)) + g.Expect(cert.MaxPathLenZero).To(BeTrue()) + + // Verify key usage + expectedKeyUsage := x509.KeyUsageKeyEncipherment | x509.KeyUsageDigitalSignature + g.Expect(cert.KeyUsage).To(Equal(expectedKeyUsage)) + + // Verify extended key usage + g.Expect(cert.ExtKeyUsage).To(Equal([]x509.ExtKeyUsage{x509.ExtKeyUsageServerAuth})) + + // Verify validity period + if tc.duration > 0 { + g.Expect(time.Now()).To(BeTemporally("<", cert.NotAfter)) + g.Expect(time.Now()).To(BeTemporally(">", cert.NotBefore)) + } + + // Verify private key PEM block + keyBlock, _ := pem.Decode(keyPEM) + g.Expect(keyBlock).NotTo(BeNil()) + g.Expect(keyBlock.Type).To(Equal("RSA PRIVATE KEY")) + }) + } +} diff --git a/vendor/go.uber.org/mock/AUTHORS b/vendor/go.uber.org/mock/AUTHORS new file mode 100644 index 000000000000..660b8ccc8ae0 --- /dev/null +++ b/vendor/go.uber.org/mock/AUTHORS @@ -0,0 +1,12 @@ +# This is the official list of GoMock authors for copyright purposes. +# This file is distinct from the CONTRIBUTORS files. +# See the latter for an explanation. + +# Names should be added to this file as +# Name or Organization +# The email address is not required for organizations. + +# Please keep the list sorted. + +Alex Reece +Google Inc. diff --git a/vendor/go.uber.org/mock/LICENSE b/vendor/go.uber.org/mock/LICENSE new file mode 100644 index 000000000000..d64569567334 --- /dev/null +++ b/vendor/go.uber.org/mock/LICENSE @@ -0,0 +1,202 @@ + + Apache License + Version 2.0, January 2004 + http://www.apache.org/licenses/ + + TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION + + 1. Definitions. + + "License" shall mean the terms and conditions for use, reproduction, + and distribution as defined by Sections 1 through 9 of this document. + + "Licensor" shall mean the copyright owner or entity authorized by + the copyright owner that is granting the License. + + "Legal Entity" shall mean the union of the acting entity and all + other entities that control, are controlled by, or are under common + control with that entity. For the purposes of this definition, + "control" means (i) the power, direct or indirect, to cause the + direction or management of such entity, whether by contract or + otherwise, or (ii) ownership of fifty percent (50%) or more of the + outstanding shares, or (iii) beneficial ownership of such entity. + + "You" (or "Your") shall mean an individual or Legal Entity + exercising permissions granted by this License. + + "Source" form shall mean the preferred form for making modifications, + including but not limited to software source code, documentation + source, and configuration files. + + "Object" form shall mean any form resulting from mechanical + transformation or translation of a Source form, including but + not limited to compiled object code, generated documentation, + and conversions to other media types. + + "Work" shall mean the work of authorship, whether in Source or + Object form, made available under the License, as indicated by a + copyright notice that is included in or attached to the work + (an example is provided in the Appendix below). + + "Derivative Works" shall mean any work, whether in Source or Object + form, that is based on (or derived from) the Work and for which the + editorial revisions, annotations, elaborations, or other modifications + represent, as a whole, an original work of authorship. For the purposes + of this License, Derivative Works shall not include works that remain + separable from, or merely link (or bind by name) to the interfaces of, + the Work and Derivative Works thereof. + + "Contribution" shall mean any work of authorship, including + the original version of the Work and any modifications or additions + to that Work or Derivative Works thereof, that is intentionally + submitted to Licensor for inclusion in the Work by the copyright owner + or by an individual or Legal Entity authorized to submit on behalf of + the copyright owner. For the purposes of this definition, "submitted" + means any form of electronic, verbal, or written communication sent + to the Licensor or its representatives, including but not limited to + communication on electronic mailing lists, source code control systems, + and issue tracking systems that are managed by, or on behalf of, the + Licensor for the purpose of discussing and improving the Work, but + excluding communication that is conspicuously marked or otherwise + designated in writing by the copyright owner as "Not a Contribution." + + "Contributor" shall mean Licensor and any individual or Legal Entity + on behalf of whom a Contribution has been received by Licensor and + subsequently incorporated within the Work. + + 2. Grant of Copyright License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + copyright license to reproduce, prepare Derivative Works of, + publicly display, publicly perform, sublicense, and distribute the + Work and such Derivative Works in Source or Object form. + + 3. Grant of Patent License. Subject to the terms and conditions of + this License, each Contributor hereby grants to You a perpetual, + worldwide, non-exclusive, no-charge, royalty-free, irrevocable + (except as stated in this section) patent license to make, have made, + use, offer to sell, sell, import, and otherwise transfer the Work, + where such license applies only to those patent claims licensable + by such Contributor that are necessarily infringed by their + Contribution(s) alone or by combination of their Contribution(s) + with the Work to which such Contribution(s) was submitted. If You + institute patent litigation against any entity (including a + cross-claim or counterclaim in a lawsuit) alleging that the Work + or a Contribution incorporated within the Work constitutes direct + or contributory patent infringement, then any patent licenses + granted to You under this License for that Work shall terminate + as of the date such litigation is filed. + + 4. Redistribution. You may reproduce and distribute copies of the + Work or Derivative Works thereof in any medium, with or without + modifications, and in Source or Object form, provided that You + meet the following conditions: + + (a) You must give any other recipients of the Work or + Derivative Works a copy of this License; and + + (b) You must cause any modified files to carry prominent notices + stating that You changed the files; and + + (c) You must retain, in the Source form of any Derivative Works + that You distribute, all copyright, patent, trademark, and + attribution notices from the Source form of the Work, + excluding those notices that do not pertain to any part of + the Derivative Works; and + + (d) If the Work includes a "NOTICE" text file as part of its + distribution, then any Derivative Works that You distribute must + include a readable copy of the attribution notices contained + within such NOTICE file, excluding those notices that do not + pertain to any part of the Derivative Works, in at least one + of the following places: within a NOTICE text file distributed + as part of the Derivative Works; within the Source form or + documentation, if provided along with the Derivative Works; or, + within a display generated by the Derivative Works, if and + wherever such third-party notices normally appear. The contents + of the NOTICE file are for informational purposes only and + do not modify the License. You may add Your own attribution + notices within Derivative Works that You distribute, alongside + or as an addendum to the NOTICE text from the Work, provided + that such additional attribution notices cannot be construed + as modifying the License. + + You may add Your own copyright statement to Your modifications and + may provide additional or different license terms and conditions + for use, reproduction, or distribution of Your modifications, or + for any such Derivative Works as a whole, provided Your use, + reproduction, and distribution of the Work otherwise complies with + the conditions stated in this License. + + 5. Submission of Contributions. Unless You explicitly state otherwise, + any Contribution intentionally submitted for inclusion in the Work + by You to the Licensor shall be under the terms and conditions of + this License, without any additional terms or conditions. + Notwithstanding the above, nothing herein shall supersede or modify + the terms of any separate license agreement you may have executed + with Licensor regarding such Contributions. + + 6. Trademarks. This License does not grant permission to use the trade + names, trademarks, service marks, or product names of the Licensor, + except as required for reasonable and customary use in describing the + origin of the Work and reproducing the content of the NOTICE file. + + 7. Disclaimer of Warranty. Unless required by applicable law or + agreed to in writing, Licensor provides the Work (and each + Contributor provides its Contributions) on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or + implied, including, without limitation, any warranties or conditions + of TITLE, NON-INFRINGEMENT, MERCHANTABILITY, or FITNESS FOR A + PARTICULAR PURPOSE. You are solely responsible for determining the + appropriateness of using or redistributing the Work and assume any + risks associated with Your exercise of permissions under this License. + + 8. Limitation of Liability. In no event and under no legal theory, + whether in tort (including negligence), contract, or otherwise, + unless required by applicable law (such as deliberate and grossly + negligent acts) or agreed to in writing, shall any Contributor be + liable to You for damages, including any direct, indirect, special, + incidental, or consequential damages of any character arising as a + result of this License or out of the use or inability to use the + Work (including but not limited to damages for loss of goodwill, + work stoppage, computer failure or malfunction, or any and all + other commercial damages or losses), even if such Contributor + has been advised of the possibility of such damages. + + 9. Accepting Warranty or Additional Liability. While redistributing + the Work or Derivative Works thereof, You may choose to offer, + and charge a fee for, acceptance of support, warranty, indemnity, + or other liability obligations and/or rights consistent with this + License. However, in accepting such obligations, You may act only + on Your own behalf and on Your sole responsibility, not on behalf + of any other Contributor, and only if You agree to indemnify, + defend, and hold each Contributor harmless for any liability + incurred by, or claims asserted against, such Contributor by reason + of your accepting any such warranty or additional liability. + + END OF TERMS AND CONDITIONS + + APPENDIX: How to apply the Apache License to your work. + + To apply the Apache License to your work, attach the following + boilerplate notice, with the fields enclosed by brackets "[]" + replaced with your own identifying information. (Don't include + the brackets!) The text should be enclosed in the appropriate + comment syntax for the file format. We also recommend that a + file or class name and description of purpose be included on the + same "printed page" as the copyright notice for easier + identification within third-party archives. + + Copyright [yyyy] [name of copyright owner] + + Licensed under the Apache License, Version 2.0 (the "License"); + you may not use this file except in compliance with the License. + You may obtain a copy of the License at + + http://www.apache.org/licenses/LICENSE-2.0 + + Unless required by applicable law or agreed to in writing, software + distributed under the License is distributed on an "AS IS" BASIS, + WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. + See the License for the specific language governing permissions and + limitations under the License. diff --git a/vendor/go.uber.org/mock/gomock/call.go b/vendor/go.uber.org/mock/gomock/call.go new file mode 100644 index 000000000000..e1ea82637718 --- /dev/null +++ b/vendor/go.uber.org/mock/gomock/call.go @@ -0,0 +1,508 @@ +// Copyright 2010 Google Inc. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package gomock + +import ( + "fmt" + "reflect" + "strconv" + "strings" +) + +// Call represents an expected call to a mock. +type Call struct { + t TestHelper // for triggering test failures on invalid call setup + + receiver any // the receiver of the method call + method string // the name of the method + methodType reflect.Type // the type of the method + args []Matcher // the args + origin string // file and line number of call setup + + preReqs []*Call // prerequisite calls + + // Expectations + minCalls, maxCalls int + + numCalls int // actual number made + + // actions are called when this Call is called. Each action gets the args and + // can set the return values by returning a non-nil slice. Actions run in the + // order they are created. + actions []func([]any) []any +} + +// newCall creates a *Call. It requires the method type in order to support +// unexported methods. +func newCall(t TestHelper, receiver any, method string, methodType reflect.Type, args ...any) *Call { + t.Helper() + + // TODO: check arity, types. + mArgs := make([]Matcher, len(args)) + for i, arg := range args { + if m, ok := arg.(Matcher); ok { + mArgs[i] = m + } else if arg == nil { + // Handle nil specially so that passing a nil interface value + // will match the typed nils of concrete args. + mArgs[i] = Nil() + } else { + mArgs[i] = Eq(arg) + } + } + + // callerInfo's skip should be updated if the number of calls between the user's test + // and this line changes, i.e. this code is wrapped in another anonymous function. + // 0 is us, 1 is RecordCallWithMethodType(), 2 is the generated recorder, and 3 is the user's test. + origin := callerInfo(3) + actions := []func([]any) []any{func([]any) []any { + // Synthesize the zero value for each of the return args' types. + rets := make([]any, methodType.NumOut()) + for i := 0; i < methodType.NumOut(); i++ { + rets[i] = reflect.Zero(methodType.Out(i)).Interface() + } + return rets + }} + return &Call{t: t, receiver: receiver, method: method, methodType: methodType, + args: mArgs, origin: origin, minCalls: 1, maxCalls: 1, actions: actions} +} + +// AnyTimes allows the expectation to be called 0 or more times +func (c *Call) AnyTimes() *Call { + c.minCalls, c.maxCalls = 0, 1e8 // close enough to infinity + return c +} + +// MinTimes requires the call to occur at least n times. If AnyTimes or MaxTimes have not been called or if MaxTimes +// was previously called with 1, MinTimes also sets the maximum number of calls to infinity. +func (c *Call) MinTimes(n int) *Call { + c.minCalls = n + if c.maxCalls == 1 { + c.maxCalls = 1e8 + } + return c +} + +// MaxTimes limits the number of calls to n times. If AnyTimes or MinTimes have not been called or if MinTimes was +// previously called with 1, MaxTimes also sets the minimum number of calls to 0. +func (c *Call) MaxTimes(n int) *Call { + c.maxCalls = n + if c.minCalls == 1 { + c.minCalls = 0 + } + return c +} + +// DoAndReturn declares the action to run when the call is matched. +// The return values from this function are returned by the mocked function. +// It takes an any argument to support n-arity functions. +// The anonymous function must match the function signature mocked method. +func (c *Call) DoAndReturn(f any) *Call { + // TODO: Check arity and types here, rather than dying badly elsewhere. + v := reflect.ValueOf(f) + + c.addAction(func(args []any) []any { + c.t.Helper() + ft := v.Type() + if c.methodType.NumIn() != ft.NumIn() { + if ft.IsVariadic() { + c.t.Fatalf("wrong number of arguments in DoAndReturn func for %T.%v The function signature must match the mocked method, a variadic function cannot be used.", + c.receiver, c.method) + } else { + c.t.Fatalf("wrong number of arguments in DoAndReturn func for %T.%v: got %d, want %d [%s]", + c.receiver, c.method, ft.NumIn(), c.methodType.NumIn(), c.origin) + } + return nil + } + vArgs := make([]reflect.Value, len(args)) + for i := 0; i < len(args); i++ { + if args[i] != nil { + vArgs[i] = reflect.ValueOf(args[i]) + } else { + // Use the zero value for the arg. + vArgs[i] = reflect.Zero(ft.In(i)) + } + } + vRets := v.Call(vArgs) + rets := make([]any, len(vRets)) + for i, ret := range vRets { + rets[i] = ret.Interface() + } + return rets + }) + return c +} + +// Do declares the action to run when the call is matched. The function's +// return values are ignored to retain backward compatibility. To use the +// return values call DoAndReturn. +// It takes an any argument to support n-arity functions. +// The anonymous function must match the function signature mocked method. +func (c *Call) Do(f any) *Call { + // TODO: Check arity and types here, rather than dying badly elsewhere. + v := reflect.ValueOf(f) + + c.addAction(func(args []any) []any { + c.t.Helper() + ft := v.Type() + if c.methodType.NumIn() != ft.NumIn() { + if ft.IsVariadic() { + c.t.Fatalf("wrong number of arguments in Do func for %T.%v The function signature must match the mocked method, a variadic function cannot be used.", + c.receiver, c.method) + } else { + c.t.Fatalf("wrong number of arguments in Do func for %T.%v: got %d, want %d [%s]", + c.receiver, c.method, ft.NumIn(), c.methodType.NumIn(), c.origin) + } + return nil + } + vArgs := make([]reflect.Value, len(args)) + for i := 0; i < len(args); i++ { + if args[i] != nil { + vArgs[i] = reflect.ValueOf(args[i]) + } else { + // Use the zero value for the arg. + vArgs[i] = reflect.Zero(ft.In(i)) + } + } + v.Call(vArgs) + return nil + }) + return c +} + +// Return declares the values to be returned by the mocked function call. +func (c *Call) Return(rets ...any) *Call { + c.t.Helper() + + mt := c.methodType + if len(rets) != mt.NumOut() { + c.t.Fatalf("wrong number of arguments to Return for %T.%v: got %d, want %d [%s]", + c.receiver, c.method, len(rets), mt.NumOut(), c.origin) + } + for i, ret := range rets { + if got, want := reflect.TypeOf(ret), mt.Out(i); got == want { + // Identical types; nothing to do. + } else if got == nil { + // Nil needs special handling. + switch want.Kind() { + case reflect.Chan, reflect.Func, reflect.Interface, reflect.Map, reflect.Ptr, reflect.Slice: + // ok + default: + c.t.Fatalf("argument %d to Return for %T.%v is nil, but %v is not nillable [%s]", + i, c.receiver, c.method, want, c.origin) + } + } else if got.AssignableTo(want) { + // Assignable type relation. Make the assignment now so that the generated code + // can return the values with a type assertion. + v := reflect.New(want).Elem() + v.Set(reflect.ValueOf(ret)) + rets[i] = v.Interface() + } else { + c.t.Fatalf("wrong type of argument %d to Return for %T.%v: %v is not assignable to %v [%s]", + i, c.receiver, c.method, got, want, c.origin) + } + } + + c.addAction(func([]any) []any { + return rets + }) + + return c +} + +// Times declares the exact number of times a function call is expected to be executed. +func (c *Call) Times(n int) *Call { + c.minCalls, c.maxCalls = n, n + return c +} + +// SetArg declares an action that will set the nth argument's value, +// indirected through a pointer. Or, in the case of a slice and map, SetArg +// will copy value's elements/key-value pairs into the nth argument. +func (c *Call) SetArg(n int, value any) *Call { + c.t.Helper() + + mt := c.methodType + // TODO: This will break on variadic methods. + // We will need to check those at invocation time. + if n < 0 || n >= mt.NumIn() { + c.t.Fatalf("SetArg(%d, ...) called for a method with %d args [%s]", + n, mt.NumIn(), c.origin) + } + // Permit setting argument through an interface. + // In the interface case, we don't (nay, can't) check the type here. + at := mt.In(n) + switch at.Kind() { + case reflect.Ptr: + dt := at.Elem() + if vt := reflect.TypeOf(value); !vt.AssignableTo(dt) { + c.t.Fatalf("SetArg(%d, ...) argument is a %v, not assignable to %v [%s]", + n, vt, dt, c.origin) + } + case reflect.Interface: + // nothing to do + case reflect.Slice: + // nothing to do + case reflect.Map: + // nothing to do + default: + c.t.Fatalf("SetArg(%d, ...) referring to argument of non-pointer non-interface non-slice non-map type %v [%s]", + n, at, c.origin) + } + + c.addAction(func(args []any) []any { + v := reflect.ValueOf(value) + switch reflect.TypeOf(args[n]).Kind() { + case reflect.Slice: + setSlice(args[n], v) + case reflect.Map: + setMap(args[n], v) + default: + reflect.ValueOf(args[n]).Elem().Set(v) + } + return nil + }) + return c +} + +// isPreReq returns true if other is a direct or indirect prerequisite to c. +func (c *Call) isPreReq(other *Call) bool { + for _, preReq := range c.preReqs { + if other == preReq || preReq.isPreReq(other) { + return true + } + } + return false +} + +// After declares that the call may only match after preReq has been exhausted. +func (c *Call) After(preReq *Call) *Call { + c.t.Helper() + + if c == preReq { + c.t.Fatalf("A call isn't allowed to be its own prerequisite") + } + if preReq.isPreReq(c) { + c.t.Fatalf("Loop in call order: %v is a prerequisite to %v (possibly indirectly).", c, preReq) + } + + c.preReqs = append(c.preReqs, preReq) + return c +} + +// Returns true if the minimum number of calls have been made. +func (c *Call) satisfied() bool { + return c.numCalls >= c.minCalls +} + +// Returns true if the maximum number of calls have been made. +func (c *Call) exhausted() bool { + return c.numCalls >= c.maxCalls +} + +func (c *Call) String() string { + args := make([]string, len(c.args)) + for i, arg := range c.args { + args[i] = arg.String() + } + arguments := strings.Join(args, ", ") + return fmt.Sprintf("%T.%v(%s) %s", c.receiver, c.method, arguments, c.origin) +} + +// Tests if the given call matches the expected call. +// If yes, returns nil. If no, returns error with message explaining why it does not match. +func (c *Call) matches(args []any) error { + if !c.methodType.IsVariadic() { + if len(args) != len(c.args) { + return fmt.Errorf("expected call at %s has the wrong number of arguments. Got: %d, want: %d", + c.origin, len(args), len(c.args)) + } + + for i, m := range c.args { + if !m.Matches(args[i]) { + return fmt.Errorf( + "expected call at %s doesn't match the argument at index %d.\nGot: %v\nWant: %v", + c.origin, i, formatGottenArg(m, args[i]), m, + ) + } + } + } else { + if len(c.args) < c.methodType.NumIn()-1 { + return fmt.Errorf("expected call at %s has the wrong number of matchers. Got: %d, want: %d", + c.origin, len(c.args), c.methodType.NumIn()-1) + } + if len(c.args) != c.methodType.NumIn() && len(args) != len(c.args) { + return fmt.Errorf("expected call at %s has the wrong number of arguments. Got: %d, want: %d", + c.origin, len(args), len(c.args)) + } + if len(args) < len(c.args)-1 { + return fmt.Errorf("expected call at %s has the wrong number of arguments. Got: %d, want: greater than or equal to %d", + c.origin, len(args), len(c.args)-1) + } + + for i, m := range c.args { + if i < c.methodType.NumIn()-1 { + // Non-variadic args + if !m.Matches(args[i]) { + return fmt.Errorf("expected call at %s doesn't match the argument at index %s.\nGot: %v\nWant: %v", + c.origin, strconv.Itoa(i), formatGottenArg(m, args[i]), m) + } + continue + } + // The last arg has a possibility of a variadic argument, so let it branch + + // sample: Foo(a int, b int, c ...int) + if i < len(c.args) && i < len(args) { + if m.Matches(args[i]) { + // Got Foo(a, b, c) want Foo(matcherA, matcherB, gomock.Any()) + // Got Foo(a, b, c) want Foo(matcherA, matcherB, someSliceMatcher) + // Got Foo(a, b, c) want Foo(matcherA, matcherB, matcherC) + // Got Foo(a, b) want Foo(matcherA, matcherB) + // Got Foo(a, b, c, d) want Foo(matcherA, matcherB, matcherC, matcherD) + continue + } + } + + // The number of actual args don't match the number of matchers, + // or the last matcher is a slice and the last arg is not. + // If this function still matches it is because the last matcher + // matches all the remaining arguments or the lack of any. + // Convert the remaining arguments, if any, into a slice of the + // expected type. + vArgsType := c.methodType.In(c.methodType.NumIn() - 1) + vArgs := reflect.MakeSlice(vArgsType, 0, len(args)-i) + for _, arg := range args[i:] { + vArgs = reflect.Append(vArgs, reflect.ValueOf(arg)) + } + if m.Matches(vArgs.Interface()) { + // Got Foo(a, b, c, d, e) want Foo(matcherA, matcherB, gomock.Any()) + // Got Foo(a, b, c, d, e) want Foo(matcherA, matcherB, someSliceMatcher) + // Got Foo(a, b) want Foo(matcherA, matcherB, gomock.Any()) + // Got Foo(a, b) want Foo(matcherA, matcherB, someEmptySliceMatcher) + break + } + // Wrong number of matchers or not match. Fail. + // Got Foo(a, b) want Foo(matcherA, matcherB, matcherC, matcherD) + // Got Foo(a, b, c) want Foo(matcherA, matcherB, matcherC, matcherD) + // Got Foo(a, b, c, d) want Foo(matcherA, matcherB, matcherC, matcherD, matcherE) + // Got Foo(a, b, c, d, e) want Foo(matcherA, matcherB, matcherC, matcherD) + // Got Foo(a, b, c) want Foo(matcherA, matcherB) + + return fmt.Errorf("expected call at %s doesn't match the argument at index %s.\nGot: %v\nWant: %v", + c.origin, strconv.Itoa(i), formatGottenArg(m, args[i:]), c.args[i]) + } + } + + // Check that all prerequisite calls have been satisfied. + for _, preReqCall := range c.preReqs { + if !preReqCall.satisfied() { + return fmt.Errorf("expected call at %s doesn't have a prerequisite call satisfied:\n%v\nshould be called before:\n%v", + c.origin, preReqCall, c) + } + } + + // Check that the call is not exhausted. + if c.exhausted() { + return fmt.Errorf("expected call at %s has already been called the max number of times", c.origin) + } + + return nil +} + +// dropPrereqs tells the expected Call to not re-check prerequisite calls any +// longer, and to return its current set. +func (c *Call) dropPrereqs() (preReqs []*Call) { + preReqs = c.preReqs + c.preReqs = nil + return +} + +func (c *Call) call() []func([]any) []any { + c.numCalls++ + return c.actions +} + +// InOrder declares that the given calls should occur in order. +// It panics if the type of any of the arguments isn't *Call or a generated +// mock with an embedded *Call. +func InOrder(args ...any) { + calls := make([]*Call, 0, len(args)) + for i := 0; i < len(args); i++ { + if call := getCall(args[i]); call != nil { + calls = append(calls, call) + continue + } + panic(fmt.Sprintf( + "invalid argument at position %d of type %T, InOrder expects *gomock.Call or generated mock types with an embedded *gomock.Call", + i, + args[i], + )) + } + for i := 1; i < len(calls); i++ { + calls[i].After(calls[i-1]) + } +} + +// getCall checks if the parameter is a *Call or a generated struct +// that wraps a *Call and returns the *Call pointer - if neither, it returns nil. +func getCall(arg any) *Call { + if call, ok := arg.(*Call); ok { + return call + } + t := reflect.ValueOf(arg) + if t.Kind() != reflect.Ptr && t.Kind() != reflect.Interface { + return nil + } + t = t.Elem() + for i := 0; i < t.NumField(); i++ { + f := t.Field(i) + if !f.CanInterface() { + continue + } + if call, ok := f.Interface().(*Call); ok { + return call + } + } + return nil +} + +func setSlice(arg any, v reflect.Value) { + va := reflect.ValueOf(arg) + for i := 0; i < v.Len(); i++ { + va.Index(i).Set(v.Index(i)) + } +} + +func setMap(arg any, v reflect.Value) { + va := reflect.ValueOf(arg) + for _, e := range va.MapKeys() { + va.SetMapIndex(e, reflect.Value{}) + } + for _, e := range v.MapKeys() { + va.SetMapIndex(e, v.MapIndex(e)) + } +} + +func (c *Call) addAction(action func([]any) []any) { + c.actions = append(c.actions, action) +} + +func formatGottenArg(m Matcher, arg any) string { + got := fmt.Sprintf("%v (%T)", arg, arg) + if gs, ok := m.(GotFormatter); ok { + got = gs.Got(arg) + } + return got +} diff --git a/vendor/go.uber.org/mock/gomock/callset.go b/vendor/go.uber.org/mock/gomock/callset.go new file mode 100644 index 000000000000..f5cc592d6f40 --- /dev/null +++ b/vendor/go.uber.org/mock/gomock/callset.go @@ -0,0 +1,164 @@ +// Copyright 2011 Google Inc. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package gomock + +import ( + "bytes" + "errors" + "fmt" + "sync" +) + +// callSet represents a set of expected calls, indexed by receiver and method +// name. +type callSet struct { + // Calls that are still expected. + expected map[callSetKey][]*Call + expectedMu *sync.Mutex + // Calls that have been exhausted. + exhausted map[callSetKey][]*Call + // when set to true, existing call expectations are overridden when new call expectations are made + allowOverride bool +} + +// callSetKey is the key in the maps in callSet +type callSetKey struct { + receiver any + fname string +} + +func newCallSet() *callSet { + return &callSet{ + expected: make(map[callSetKey][]*Call), + expectedMu: &sync.Mutex{}, + exhausted: make(map[callSetKey][]*Call), + } +} + +func newOverridableCallSet() *callSet { + return &callSet{ + expected: make(map[callSetKey][]*Call), + expectedMu: &sync.Mutex{}, + exhausted: make(map[callSetKey][]*Call), + allowOverride: true, + } +} + +// Add adds a new expected call. +func (cs callSet) Add(call *Call) { + key := callSetKey{call.receiver, call.method} + + cs.expectedMu.Lock() + defer cs.expectedMu.Unlock() + + m := cs.expected + if call.exhausted() { + m = cs.exhausted + } + if cs.allowOverride { + m[key] = make([]*Call, 0) + } + + m[key] = append(m[key], call) +} + +// Remove removes an expected call. +func (cs callSet) Remove(call *Call) { + key := callSetKey{call.receiver, call.method} + + cs.expectedMu.Lock() + defer cs.expectedMu.Unlock() + + calls := cs.expected[key] + for i, c := range calls { + if c == call { + // maintain order for remaining calls + cs.expected[key] = append(calls[:i], calls[i+1:]...) + cs.exhausted[key] = append(cs.exhausted[key], call) + break + } + } +} + +// FindMatch searches for a matching call. Returns error with explanation message if no call matched. +func (cs callSet) FindMatch(receiver any, method string, args []any) (*Call, error) { + key := callSetKey{receiver, method} + + cs.expectedMu.Lock() + defer cs.expectedMu.Unlock() + + // Search through the expected calls. + expected := cs.expected[key] + var callsErrors bytes.Buffer + for _, call := range expected { + err := call.matches(args) + if err != nil { + _, _ = fmt.Fprintf(&callsErrors, "\n%v", err) + } else { + return call, nil + } + } + + // If we haven't found a match then search through the exhausted calls so we + // get useful error messages. + exhausted := cs.exhausted[key] + for _, call := range exhausted { + if err := call.matches(args); err != nil { + _, _ = fmt.Fprintf(&callsErrors, "\n%v", err) + continue + } + _, _ = fmt.Fprintf( + &callsErrors, "all expected calls for method %q have been exhausted", method, + ) + } + + if len(expected)+len(exhausted) == 0 { + _, _ = fmt.Fprintf(&callsErrors, "there are no expected calls of the method %q for that receiver", method) + } + + return nil, errors.New(callsErrors.String()) +} + +// Failures returns the calls that are not satisfied. +func (cs callSet) Failures() []*Call { + cs.expectedMu.Lock() + defer cs.expectedMu.Unlock() + + failures := make([]*Call, 0, len(cs.expected)) + for _, calls := range cs.expected { + for _, call := range calls { + if !call.satisfied() { + failures = append(failures, call) + } + } + } + return failures +} + +// Satisfied returns true in case all expected calls in this callSet are satisfied. +func (cs callSet) Satisfied() bool { + cs.expectedMu.Lock() + defer cs.expectedMu.Unlock() + + for _, calls := range cs.expected { + for _, call := range calls { + if !call.satisfied() { + return false + } + } + } + + return true +} diff --git a/vendor/go.uber.org/mock/gomock/controller.go b/vendor/go.uber.org/mock/gomock/controller.go new file mode 100644 index 000000000000..9d17a2f0c79f --- /dev/null +++ b/vendor/go.uber.org/mock/gomock/controller.go @@ -0,0 +1,318 @@ +// Copyright 2010 Google Inc. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package gomock + +import ( + "context" + "fmt" + "reflect" + "runtime" + "sync" +) + +// A TestReporter is something that can be used to report test failures. It +// is satisfied by the standard library's *testing.T. +type TestReporter interface { + Errorf(format string, args ...any) + Fatalf(format string, args ...any) +} + +// TestHelper is a TestReporter that has the Helper method. It is satisfied +// by the standard library's *testing.T. +type TestHelper interface { + TestReporter + Helper() +} + +// cleanuper is used to check if TestHelper also has the `Cleanup` method. A +// common pattern is to pass in a `*testing.T` to +// `NewController(t TestReporter)`. In Go 1.14+, `*testing.T` has a cleanup +// method. This can be utilized to call `Finish()` so the caller of this library +// does not have to. +type cleanuper interface { + Cleanup(func()) +} + +// A Controller represents the top-level control of a mock ecosystem. It +// defines the scope and lifetime of mock objects, as well as their +// expectations. It is safe to call Controller's methods from multiple +// goroutines. Each test should create a new Controller and invoke Finish via +// defer. +// +// func TestFoo(t *testing.T) { +// ctrl := gomock.NewController(t) +// // .. +// } +// +// func TestBar(t *testing.T) { +// t.Run("Sub-Test-1", st) { +// ctrl := gomock.NewController(st) +// // .. +// }) +// t.Run("Sub-Test-2", st) { +// ctrl := gomock.NewController(st) +// // .. +// }) +// }) +type Controller struct { + // T should only be called within a generated mock. It is not intended to + // be used in user code and may be changed in future versions. T is the + // TestReporter passed in when creating the Controller via NewController. + // If the TestReporter does not implement a TestHelper it will be wrapped + // with a nopTestHelper. + T TestHelper + mu sync.Mutex + expectedCalls *callSet + finished bool +} + +// NewController returns a new Controller. It is the preferred way to create a Controller. +// +// Passing [*testing.T] registers cleanup function to automatically call [Controller.Finish] +// when the test and all its subtests complete. +func NewController(t TestReporter, opts ...ControllerOption) *Controller { + h, ok := t.(TestHelper) + if !ok { + h = &nopTestHelper{t} + } + ctrl := &Controller{ + T: h, + expectedCalls: newCallSet(), + } + for _, opt := range opts { + opt.apply(ctrl) + } + if c, ok := isCleanuper(ctrl.T); ok { + c.Cleanup(func() { + ctrl.T.Helper() + ctrl.finish(true, nil) + }) + } + + return ctrl +} + +// ControllerOption configures how a Controller should behave. +type ControllerOption interface { + apply(*Controller) +} + +type overridableExpectationsOption struct{} + +// WithOverridableExpectations allows for overridable call expectations +// i.e., subsequent call expectations override existing call expectations +func WithOverridableExpectations() overridableExpectationsOption { + return overridableExpectationsOption{} +} + +func (o overridableExpectationsOption) apply(ctrl *Controller) { + ctrl.expectedCalls = newOverridableCallSet() +} + +type cancelReporter struct { + t TestHelper + cancel func() +} + +func (r *cancelReporter) Errorf(format string, args ...any) { + r.t.Errorf(format, args...) +} +func (r *cancelReporter) Fatalf(format string, args ...any) { + defer r.cancel() + r.t.Fatalf(format, args...) +} + +func (r *cancelReporter) Helper() { + r.t.Helper() +} + +// WithContext returns a new Controller and a Context, which is cancelled on any +// fatal failure. +func WithContext(ctx context.Context, t TestReporter) (*Controller, context.Context) { + h, ok := t.(TestHelper) + if !ok { + h = &nopTestHelper{t: t} + } + + ctx, cancel := context.WithCancel(ctx) + return NewController(&cancelReporter{t: h, cancel: cancel}), ctx +} + +type nopTestHelper struct { + t TestReporter +} + +func (h *nopTestHelper) Errorf(format string, args ...any) { + h.t.Errorf(format, args...) +} +func (h *nopTestHelper) Fatalf(format string, args ...any) { + h.t.Fatalf(format, args...) +} + +func (h nopTestHelper) Helper() {} + +// RecordCall is called by a mock. It should not be called by user code. +func (ctrl *Controller) RecordCall(receiver any, method string, args ...any) *Call { + ctrl.T.Helper() + + recv := reflect.ValueOf(receiver) + for i := 0; i < recv.Type().NumMethod(); i++ { + if recv.Type().Method(i).Name == method { + return ctrl.RecordCallWithMethodType(receiver, method, recv.Method(i).Type(), args...) + } + } + ctrl.T.Fatalf("gomock: failed finding method %s on %T", method, receiver) + panic("unreachable") +} + +// RecordCallWithMethodType is called by a mock. It should not be called by user code. +func (ctrl *Controller) RecordCallWithMethodType(receiver any, method string, methodType reflect.Type, args ...any) *Call { + ctrl.T.Helper() + + call := newCall(ctrl.T, receiver, method, methodType, args...) + + ctrl.mu.Lock() + defer ctrl.mu.Unlock() + ctrl.expectedCalls.Add(call) + + return call +} + +// Call is called by a mock. It should not be called by user code. +func (ctrl *Controller) Call(receiver any, method string, args ...any) []any { + ctrl.T.Helper() + + // Nest this code so we can use defer to make sure the lock is released. + actions := func() []func([]any) []any { + ctrl.T.Helper() + ctrl.mu.Lock() + defer ctrl.mu.Unlock() + + expected, err := ctrl.expectedCalls.FindMatch(receiver, method, args) + if err != nil { + // callerInfo's skip should be updated if the number of calls between the user's test + // and this line changes, i.e. this code is wrapped in another anonymous function. + // 0 is us, 1 is controller.Call(), 2 is the generated mock, and 3 is the user's test. + origin := callerInfo(3) + ctrl.T.Fatalf("Unexpected call to %T.%v(%v) at %s because: %s", receiver, method, args, origin, err) + } + + // Two things happen here: + // * the matching call no longer needs to check prerequite calls, + // * and the prerequite calls are no longer expected, so remove them. + preReqCalls := expected.dropPrereqs() + for _, preReqCall := range preReqCalls { + ctrl.expectedCalls.Remove(preReqCall) + } + + actions := expected.call() + if expected.exhausted() { + ctrl.expectedCalls.Remove(expected) + } + return actions + }() + + var rets []any + for _, action := range actions { + if r := action(args); r != nil { + rets = r + } + } + + return rets +} + +// Finish checks to see if all the methods that were expected to be called were called. +// It is not idempotent and therefore can only be invoked once. +func (ctrl *Controller) Finish() { + // If we're currently panicking, probably because this is a deferred call. + // This must be recovered in the deferred function. + err := recover() + ctrl.finish(false, err) +} + +// Satisfied returns whether all expected calls bound to this Controller have been satisfied. +// Calling Finish is then guaranteed to not fail due to missing calls. +func (ctrl *Controller) Satisfied() bool { + ctrl.mu.Lock() + defer ctrl.mu.Unlock() + return ctrl.expectedCalls.Satisfied() +} + +func (ctrl *Controller) finish(cleanup bool, panicErr any) { + ctrl.T.Helper() + + ctrl.mu.Lock() + defer ctrl.mu.Unlock() + + if ctrl.finished { + if _, ok := isCleanuper(ctrl.T); !ok { + ctrl.T.Fatalf("Controller.Finish was called more than once. It has to be called exactly once.") + } + return + } + ctrl.finished = true + + // Short-circuit, pass through the panic. + if panicErr != nil { + panic(panicErr) + } + + // Check that all remaining expected calls are satisfied. + failures := ctrl.expectedCalls.Failures() + for _, call := range failures { + ctrl.T.Errorf("missing call(s) to %v", call) + } + if len(failures) != 0 { + if !cleanup { + ctrl.T.Fatalf("aborting test due to missing call(s)") + return + } + ctrl.T.Errorf("aborting test due to missing call(s)") + } +} + +// callerInfo returns the file:line of the call site. skip is the number +// of stack frames to skip when reporting. 0 is callerInfo's call site. +func callerInfo(skip int) string { + if _, file, line, ok := runtime.Caller(skip + 1); ok { + return fmt.Sprintf("%s:%d", file, line) + } + return "unknown file" +} + +// isCleanuper checks it if t's base TestReporter has a Cleanup method. +func isCleanuper(t TestReporter) (cleanuper, bool) { + tr := unwrapTestReporter(t) + c, ok := tr.(cleanuper) + return c, ok +} + +// unwrapTestReporter unwraps TestReporter to the base implementation. +func unwrapTestReporter(t TestReporter) TestReporter { + tr := t + switch nt := t.(type) { + case *cancelReporter: + tr = nt.t + if h, check := tr.(*nopTestHelper); check { + tr = h.t + } + case *nopTestHelper: + tr = nt.t + default: + // not wrapped + } + return tr +} diff --git a/vendor/go.uber.org/mock/gomock/doc.go b/vendor/go.uber.org/mock/gomock/doc.go new file mode 100644 index 000000000000..696dda388209 --- /dev/null +++ b/vendor/go.uber.org/mock/gomock/doc.go @@ -0,0 +1,60 @@ +// Copyright 2022 Google LLC +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +// Package gomock is a mock framework for Go. +// +// Standard usage: +// +// (1) Define an interface that you wish to mock. +// type MyInterface interface { +// SomeMethod(x int64, y string) +// } +// (2) Use mockgen to generate a mock from the interface. +// (3) Use the mock in a test: +// func TestMyThing(t *testing.T) { +// mockCtrl := gomock.NewController(t) +// mockObj := something.NewMockMyInterface(mockCtrl) +// mockObj.EXPECT().SomeMethod(4, "blah") +// // pass mockObj to a real object and play with it. +// } +// +// By default, expected calls are not enforced to run in any particular order. +// Call order dependency can be enforced by use of InOrder and/or Call.After. +// Call.After can create more varied call order dependencies, but InOrder is +// often more convenient. +// +// The following examples create equivalent call order dependencies. +// +// Example of using Call.After to chain expected call order: +// +// firstCall := mockObj.EXPECT().SomeMethod(1, "first") +// secondCall := mockObj.EXPECT().SomeMethod(2, "second").After(firstCall) +// mockObj.EXPECT().SomeMethod(3, "third").After(secondCall) +// +// Example of using InOrder to declare expected call order: +// +// gomock.InOrder( +// mockObj.EXPECT().SomeMethod(1, "first"), +// mockObj.EXPECT().SomeMethod(2, "second"), +// mockObj.EXPECT().SomeMethod(3, "third"), +// ) +// +// The standard TestReporter most users will pass to `NewController` is a +// `*testing.T` from the context of the test. Note that this will use the +// standard `t.Error` and `t.Fatal` methods to report what happened in the test. +// In some cases this can leave your testing package in a weird state if global +// state is used since `t.Fatal` is like calling panic in the middle of a +// function. In these cases it is recommended that you pass in your own +// `TestReporter`. +package gomock diff --git a/vendor/go.uber.org/mock/gomock/matchers.go b/vendor/go.uber.org/mock/gomock/matchers.go new file mode 100644 index 000000000000..c17255096ad5 --- /dev/null +++ b/vendor/go.uber.org/mock/gomock/matchers.go @@ -0,0 +1,443 @@ +// Copyright 2010 Google Inc. +// +// Licensed under the Apache License, Version 2.0 (the "License"); +// you may not use this file except in compliance with the License. +// You may obtain a copy of the License at +// +// http://www.apache.org/licenses/LICENSE-2.0 +// +// Unless required by applicable law or agreed to in writing, software +// distributed under the License is distributed on an "AS IS" BASIS, +// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied. +// See the License for the specific language governing permissions and +// limitations under the License. + +package gomock + +import ( + "fmt" + "reflect" + "regexp" + "strings" +) + +// A Matcher is a representation of a class of values. +// It is used to represent the valid or expected arguments to a mocked method. +type Matcher interface { + // Matches returns whether x is a match. + Matches(x any) bool + + // String describes what the matcher matches. + String() string +} + +// WantFormatter modifies the given Matcher's String() method to the given +// Stringer. This allows for control on how the "Want" is formatted when +// printing . +func WantFormatter(s fmt.Stringer, m Matcher) Matcher { + type matcher interface { + Matches(x any) bool + } + + return struct { + matcher + fmt.Stringer + }{ + matcher: m, + Stringer: s, + } +} + +// StringerFunc type is an adapter to allow the use of ordinary functions as +// a Stringer. If f is a function with the appropriate signature, +// StringerFunc(f) is a Stringer that calls f. +type StringerFunc func() string + +// String implements fmt.Stringer. +func (f StringerFunc) String() string { + return f() +} + +// GotFormatter is used to better print failure messages. If a matcher +// implements GotFormatter, it will use the result from Got when printing +// the failure message. +type GotFormatter interface { + // Got is invoked with the received value. The result is used when + // printing the failure message. + Got(got any) string +} + +// GotFormatterFunc type is an adapter to allow the use of ordinary +// functions as a GotFormatter. If f is a function with the appropriate +// signature, GotFormatterFunc(f) is a GotFormatter that calls f. +type GotFormatterFunc func(got any) string + +// Got implements GotFormatter. +func (f GotFormatterFunc) Got(got any) string { + return f(got) +} + +// GotFormatterAdapter attaches a GotFormatter to a Matcher. +func GotFormatterAdapter(s GotFormatter, m Matcher) Matcher { + return struct { + GotFormatter + Matcher + }{ + GotFormatter: s, + Matcher: m, + } +} + +type anyMatcher struct{} + +func (anyMatcher) Matches(any) bool { + return true +} + +func (anyMatcher) String() string { + return "is anything" +} + +type condMatcher struct { + fn func(x any) bool +} + +func (c condMatcher) Matches(x any) bool { + return c.fn(x) +} + +func (condMatcher) String() string { + return "adheres to a custom condition" +} + +type eqMatcher struct { + x any +} + +func (e eqMatcher) Matches(x any) bool { + // In case, some value is nil + if e.x == nil || x == nil { + return reflect.DeepEqual(e.x, x) + } + + // Check if types assignable and convert them to common type + x1Val := reflect.ValueOf(e.x) + x2Val := reflect.ValueOf(x) + + if x1Val.Type().AssignableTo(x2Val.Type()) { + x1ValConverted := x1Val.Convert(x2Val.Type()) + return reflect.DeepEqual(x1ValConverted.Interface(), x2Val.Interface()) + } + + return false +} + +func (e eqMatcher) String() string { + return fmt.Sprintf("is equal to %v (%T)", e.x, e.x) +} + +type nilMatcher struct{} + +func (nilMatcher) Matches(x any) bool { + if x == nil { + return true + } + + v := reflect.ValueOf(x) + switch v.Kind() { + case reflect.Chan, reflect.Func, reflect.Interface, reflect.Map, + reflect.Ptr, reflect.Slice: + return v.IsNil() + } + + return false +} + +func (nilMatcher) String() string { + return "is nil" +} + +type notMatcher struct { + m Matcher +} + +func (n notMatcher) Matches(x any) bool { + return !n.m.Matches(x) +} + +func (n notMatcher) String() string { + return "not(" + n.m.String() + ")" +} + +type regexMatcher struct { + regex *regexp.Regexp +} + +func (m regexMatcher) Matches(x any) bool { + switch t := x.(type) { + case string: + return m.regex.MatchString(t) + case []byte: + return m.regex.Match(t) + default: + return false + } +} + +func (m regexMatcher) String() string { + return "matches regex " + m.regex.String() +} + +type assignableToTypeOfMatcher struct { + targetType reflect.Type +} + +func (m assignableToTypeOfMatcher) Matches(x any) bool { + return reflect.TypeOf(x).AssignableTo(m.targetType) +} + +func (m assignableToTypeOfMatcher) String() string { + return "is assignable to " + m.targetType.Name() +} + +type anyOfMatcher struct { + matchers []Matcher +} + +func (am anyOfMatcher) Matches(x any) bool { + for _, m := range am.matchers { + if m.Matches(x) { + return true + } + } + return false +} + +func (am anyOfMatcher) String() string { + ss := make([]string, 0, len(am.matchers)) + for _, matcher := range am.matchers { + ss = append(ss, matcher.String()) + } + return strings.Join(ss, " | ") +} + +type allMatcher struct { + matchers []Matcher +} + +func (am allMatcher) Matches(x any) bool { + for _, m := range am.matchers { + if !m.Matches(x) { + return false + } + } + return true +} + +func (am allMatcher) String() string { + ss := make([]string, 0, len(am.matchers)) + for _, matcher := range am.matchers { + ss = append(ss, matcher.String()) + } + return strings.Join(ss, "; ") +} + +type lenMatcher struct { + i int +} + +func (m lenMatcher) Matches(x any) bool { + v := reflect.ValueOf(x) + switch v.Kind() { + case reflect.Array, reflect.Chan, reflect.Map, reflect.Slice, reflect.String: + return v.Len() == m.i + default: + return false + } +} + +func (m lenMatcher) String() string { + return fmt.Sprintf("has length %d", m.i) +} + +type inAnyOrderMatcher struct { + x any +} + +func (m inAnyOrderMatcher) Matches(x any) bool { + given, ok := m.prepareValue(x) + if !ok { + return false + } + wanted, ok := m.prepareValue(m.x) + if !ok { + return false + } + + if given.Len() != wanted.Len() { + return false + } + + usedFromGiven := make([]bool, given.Len()) + foundFromWanted := make([]bool, wanted.Len()) + for i := 0; i < wanted.Len(); i++ { + wantedMatcher := Eq(wanted.Index(i).Interface()) + for j := 0; j < given.Len(); j++ { + if usedFromGiven[j] { + continue + } + if wantedMatcher.Matches(given.Index(j).Interface()) { + foundFromWanted[i] = true + usedFromGiven[j] = true + break + } + } + } + + missingFromWanted := 0 + for _, found := range foundFromWanted { + if !found { + missingFromWanted++ + } + } + extraInGiven := 0 + for _, used := range usedFromGiven { + if !used { + extraInGiven++ + } + } + + return extraInGiven == 0 && missingFromWanted == 0 +} + +func (m inAnyOrderMatcher) prepareValue(x any) (reflect.Value, bool) { + xValue := reflect.ValueOf(x) + switch xValue.Kind() { + case reflect.Slice, reflect.Array: + return xValue, true + default: + return reflect.Value{}, false + } +} + +func (m inAnyOrderMatcher) String() string { + return fmt.Sprintf("has the same elements as %v", m.x) +} + +// Constructors + +// All returns a composite Matcher that returns true if and only all of the +// matchers return true. +func All(ms ...Matcher) Matcher { return allMatcher{ms} } + +// Any returns a matcher that always matches. +func Any() Matcher { return anyMatcher{} } + +// Cond returns a matcher that matches when the given function returns true +// after passing it the parameter to the mock function. +// This is particularly useful in case you want to match over a field of a custom struct, or dynamic logic. +// +// Example usage: +// +// Cond(func(x any){return x.(int) == 1}).Matches(1) // returns true +// Cond(func(x any){return x.(int) == 2}).Matches(1) // returns false +func Cond(fn func(x any) bool) Matcher { return condMatcher{fn} } + +// AnyOf returns a composite Matcher that returns true if at least one of the +// matchers returns true. +// +// Example usage: +// +// AnyOf(1, 2, 3).Matches(2) // returns true +// AnyOf(1, 2, 3).Matches(10) // returns false +// AnyOf(Nil(), Len(2)).Matches(nil) // returns true +// AnyOf(Nil(), Len(2)).Matches("hi") // returns true +// AnyOf(Nil(), Len(2)).Matches("hello") // returns false +func AnyOf(xs ...any) Matcher { + ms := make([]Matcher, 0, len(xs)) + for _, x := range xs { + if m, ok := x.(Matcher); ok { + ms = append(ms, m) + } else { + ms = append(ms, Eq(x)) + } + } + return anyOfMatcher{ms} +} + +// Eq returns a matcher that matches on equality. +// +// Example usage: +// +// Eq(5).Matches(5) // returns true +// Eq(5).Matches(4) // returns false +func Eq(x any) Matcher { return eqMatcher{x} } + +// Len returns a matcher that matches on length. This matcher returns false if +// is compared to a type that is not an array, chan, map, slice, or string. +func Len(i int) Matcher { + return lenMatcher{i} +} + +// Nil returns a matcher that matches if the received value is nil. +// +// Example usage: +// +// var x *bytes.Buffer +// Nil().Matches(x) // returns true +// x = &bytes.Buffer{} +// Nil().Matches(x) // returns false +func Nil() Matcher { return nilMatcher{} } + +// Not reverses the results of its given child matcher. +// +// Example usage: +// +// Not(Eq(5)).Matches(4) // returns true +// Not(Eq(5)).Matches(5) // returns false +func Not(x any) Matcher { + if m, ok := x.(Matcher); ok { + return notMatcher{m} + } + return notMatcher{Eq(x)} +} + +// Regex checks whether parameter matches the associated regex. +// +// Example usage: +// +// Regex("[0-9]{2}:[0-9]{2}").Matches("23:02") // returns true +// Regex("[0-9]{2}:[0-9]{2}").Matches([]byte{'2', '3', ':', '0', '2'}) // returns true +// Regex("[0-9]{2}:[0-9]{2}").Matches("hello world") // returns false +// Regex("[0-9]{2}").Matches(21) // returns false as it's not a valid type +func Regex(regexStr string) Matcher { + return regexMatcher{regex: regexp.MustCompile(regexStr)} +} + +// AssignableToTypeOf is a Matcher that matches if the parameter to the mock +// function is assignable to the type of the parameter to this function. +// +// Example usage: +// +// var s fmt.Stringer = &bytes.Buffer{} +// AssignableToTypeOf(s).Matches(time.Second) // returns true +// AssignableToTypeOf(s).Matches(99) // returns false +// +// var ctx = reflect.TypeOf((*context.Context)(nil)).Elem() +// AssignableToTypeOf(ctx).Matches(context.Background()) // returns true +func AssignableToTypeOf(x any) Matcher { + if xt, ok := x.(reflect.Type); ok { + return assignableToTypeOfMatcher{xt} + } + return assignableToTypeOfMatcher{reflect.TypeOf(x)} +} + +// InAnyOrder is a Matcher that returns true for collections of the same elements ignoring the order. +// +// Example usage: +// +// InAnyOrder([]int{1, 2, 3}).Matches([]int{1, 3, 2}) // returns true +// InAnyOrder([]int{1, 2, 3}).Matches([]int{1, 2}) // returns false +func InAnyOrder(x any) Matcher { + return inAnyOrderMatcher{x} +} diff --git a/vendor/modules.txt b/vendor/modules.txt index 5cb1a1a2fb6d..7549ce55686d 100644 --- a/vendor/modules.txt +++ b/vendor/modules.txt @@ -1156,6 +1156,9 @@ go.starlark.net/resolve go.starlark.net/starlark go.starlark.net/starlarkstruct go.starlark.net/syntax +# go.uber.org/mock v0.4.0 +## explicit; go 1.20 +go.uber.org/mock/gomock # go.uber.org/multierr v1.11.0 ## explicit; go 1.19 go.uber.org/multierr