Fix re-issue for CNs whose issued cert file is missing
Renewal failed with an empty error box for any CN listed in index.txt without a corresponding pki/issued/<CN>.crt — the state you get when an index.txt is carried over from an older EasyRSA install but the issued/ files are not. Two defects: 1. EasyRSA writes its diagnostics to stdout, not stderr: print() is `printf '%s\n'`, and both die() and user_error() route through it. stderr only carries output from the tools EasyRSA shells out to, and even that is silenced under -S/--silent-ssl. _run_easyrsa built its message from stderr alone, so every EasyRSA failure reported blank. _easyrsa_diagnostics() now merges both streams (stderr first, so the specific openssl message is not what the dialog clips) and drops the version banner and blank padding. 2. EasyRSA reads the serial out of the .crt itself, so revoke-issued cannot revoke a CN whose cert file is gone — and there is nothing to add to the CRL either. has_issued_cert() now gates the revoke and CRL steps in both CliRunner._issue() and CursesApp._process_cert(); the workflow warns and goes straight to build-client-full. An explicit --revoke / TUI `r` still fails loudly rather than silently no-op. The post-build failure message now keys off whether a revoke actually happened, not off is_renewal, so it no longer claims "has been revoked" when nothing was. Adds tests/test_app_reissue.py: the TUI re-issue path had no coverage at all, and it is the path this bug was reported from. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Opus 5
parent
6b39c1209f
commit
9e5df8d9bb
+78
-3
@@ -5,14 +5,28 @@ from unittest.mock import patch, MagicMock
|
||||
from openvpncertupdate import (
|
||||
revoke_issued, build_client_full, gen_crl, copy_crl, EasyRSAError,
|
||||
is_ca_key_encrypted, resolve_ca_passphrase,
|
||||
has_issued_cert, issued_cert_path,
|
||||
)
|
||||
|
||||
|
||||
def ok_result():
|
||||
r = MagicMock(); r.returncode = 0; r.stderr = ""; return r
|
||||
r = MagicMock(); r.returncode = 0; r.stdout = ""; r.stderr = ""; return r
|
||||
|
||||
def err_result():
|
||||
r = MagicMock(); r.returncode = 1; r.stderr = "oops"; return r
|
||||
def err_result(stdout="", stderr="oops"):
|
||||
r = MagicMock(); r.returncode = 1; r.stdout = stdout; r.stderr = stderr; return r
|
||||
|
||||
|
||||
# EasyRSA's print() is `printf '%s\n'` -> stdout, and both user_error() and
|
||||
# die() route through it, so this is what a real failure looks like on the wire.
|
||||
EASYRSA_USER_ERROR = """
|
||||
EasyRSA version 3.2.6
|
||||
|
||||
Error
|
||||
-----
|
||||
Unable to revoke as no certificate was found.
|
||||
Certificate was expected at:
|
||||
* /etc/easy-rsa/pki/issued/alice.crt
|
||||
"""
|
||||
|
||||
|
||||
@patch("openvpncertupdate.subprocess.run")
|
||||
@@ -43,6 +57,43 @@ def test_revoke_raises_on_failure(mock_run):
|
||||
revoke_issued("/er", "/pki", "alice", "")
|
||||
|
||||
|
||||
@patch("openvpncertupdate.subprocess.run")
|
||||
def test_error_reports_easyrsa_stdout_diagnostics(mock_run):
|
||||
# EasyRSA writes its diagnostics to stdout; reporting stderr alone left the
|
||||
# user with a blank error box.
|
||||
mock_run.return_value = err_result(stdout=EASYRSA_USER_ERROR, stderr="")
|
||||
with pytest.raises(EasyRSAError) as exc:
|
||||
revoke_issued("/er", "/pki", "alice", "")
|
||||
msg = str(exc.value)
|
||||
assert "Unable to revoke as no certificate was found." in msg
|
||||
assert "* /etc/easy-rsa/pki/issued/alice.crt" in msg
|
||||
|
||||
|
||||
@patch("openvpncertupdate.subprocess.run")
|
||||
def test_error_strips_banner_and_blank_padding(mock_run):
|
||||
mock_run.return_value = err_result(stdout=EASYRSA_USER_ERROR, stderr="")
|
||||
with pytest.raises(EasyRSAError) as exc:
|
||||
revoke_issued("/er", "/pki", "alice", "")
|
||||
lines = str(exc.value).splitlines()
|
||||
assert "" not in lines # no blank padding
|
||||
assert not any(l.startswith("EasyRSA version") for l in lines)
|
||||
assert "-----" not in lines # no rule under "Error"
|
||||
|
||||
|
||||
@patch("openvpncertupdate.subprocess.run")
|
||||
def test_error_keeps_both_streams(mock_run):
|
||||
# openssl failures land on stderr while EasyRSA's die() text lands on stdout.
|
||||
mock_run.return_value = err_result(
|
||||
stdout="Easy-RSA error:\n\nFailed to revoke certificate.",
|
||||
stderr="unable to load CA private key",
|
||||
)
|
||||
with pytest.raises(EasyRSAError) as exc:
|
||||
revoke_issued("/er", "/pki", "alice", "")
|
||||
msg = str(exc.value)
|
||||
assert "Failed to revoke certificate." in msg
|
||||
assert "unable to load CA private key" in msg
|
||||
|
||||
|
||||
@patch("openvpncertupdate.subprocess.run")
|
||||
def test_build_client_full_args(mock_run):
|
||||
mock_run.return_value = ok_result()
|
||||
@@ -99,6 +150,30 @@ def test_copy_crl_restorecon_failure_is_non_fatal(mock_chmod, mock_copy, mock_ru
|
||||
mock_chmod.assert_called_once()
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# has_issued_cert
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
def test_issued_cert_path(tmp_path):
|
||||
assert issued_cert_path("/pki", "y.kuts") == "/pki/issued/y.kuts.crt"
|
||||
|
||||
|
||||
def test_has_issued_cert_true_when_file_present(tmp_path):
|
||||
issued = tmp_path / "issued"
|
||||
issued.mkdir()
|
||||
(issued / "y.kuts.crt").write_text("-----BEGIN CERTIFICATE-----\n")
|
||||
assert has_issued_cert(str(tmp_path), "y.kuts") is True
|
||||
|
||||
|
||||
def test_has_issued_cert_false_when_index_lists_cert_but_file_is_gone(tmp_path):
|
||||
(tmp_path / "issued").mkdir()
|
||||
assert has_issued_cert(str(tmp_path), "y.kuts") is False
|
||||
|
||||
|
||||
def test_has_issued_cert_false_when_issued_dir_missing(tmp_path):
|
||||
assert has_issued_cert(str(tmp_path), "y.kuts") is False
|
||||
|
||||
|
||||
# ---------------------------------------------------------------------------
|
||||
# is_ca_key_encrypted
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
Reference in New Issue
Block a user