Fixing RO Security Vulnerabilities
[osm/RO.git] / NG-RO / osm_ng_ro / tests / test_ns.py
index 129e668..e69a4c5 100644 (file)
 import unittest
 from unittest.mock import MagicMock, Mock, patch
 
-from jinja2 import TemplateError, TemplateNotFound, UndefinedError
+from jinja2 import (
+    Environment,
+    select_autoescape,
+    StrictUndefined,
+    TemplateError,
+    TemplateNotFound,
+    UndefinedError,
+)
 from osm_ng_ro.ns import Ns, NsException
 
 
@@ -1408,8 +1415,15 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         target_flavor = {}
-        indata = {}
+        indata = {
+            "vnf": [
+                {
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+                },
+            ],
+        }
         vim_info = {}
         target_record_id = ""
 
@@ -1428,6 +1442,7 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         target_flavor = {
             "no-target-flavor": "here",
         }
@@ -1450,6 +1465,7 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1494,6 +1510,7 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1540,6 +1557,52 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+        db = MagicMock(name="database mock")
+        kwargs = {
+            "db": db,
+        }
+
+        db.get_one.return_value = {
+            "_id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+            "df": [
+                {
+                    "id": "default-df",
+                    "vdu-profile": [
+                        {"id": "without_volumes-VM", "min-number-of-instances": 1}
+                    ],
+                }
+            ],
+            "id": "without_volumes-vnf",
+            "product-name": "without_volumes-vnf",
+            "vdu": [
+                {
+                    "id": "without_volumes-VM",
+                    "name": "without_volumes-VM",
+                    "sw-image-desc": "ubuntu20.04",
+                    "alternative-sw-image-desc": [
+                        "ubuntu20.04-aws",
+                        "ubuntu20.04-azure",
+                    ],
+                    "virtual-storage-desc": ["root-volume", "ephemeral-volume"],
+                }
+            ],
+            "version": "1.0",
+            "virtual-storage-desc": [
+                {"id": "root-volume", "size-of-storage": "10"},
+                {
+                    "id": "ephemeral-volume",
+                    "type-of-storage": "etsi-nfv-descriptors:ephemeral-storage",
+                    "size-of-storage": "1",
+                },
+            ],
+            "_admin": {
+                "storage": {
+                    "fs": "mongo",
+                    "path": "/app/storage/",
+                },
+                "type": "vnfd",
+            },
+        }
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1580,6 +1643,7 @@ class TestNs(unittest.TestCase):
                             ],
                         },
                     ],
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
                 },
             ],
         }
@@ -1593,6 +1657,7 @@ class TestNs(unittest.TestCase):
             indata=indata,
             vim_info=vim_info,
             target_record_id=target_record_id,
+            **kwargs,
         )
 
         self.assertTrue(epa_params.called)
@@ -1603,6 +1668,7 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1643,6 +1709,118 @@ class TestNs(unittest.TestCase):
                             ],
                         },
                     ],
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+                },
+            ],
+        }
+        vim_info = {}
+        target_record_id = ""
+
+        epa_params.return_value = {}
+
+        result = Ns._process_flavor_params(
+            target_flavor=target_flavor,
+            indata=indata,
+            vim_info=vim_info,
+            target_record_id=target_record_id,
+        )
+
+        self.assertTrue(epa_params.called)
+        self.assertDictEqual(result, expected_result)
+
+    @patch("osm_ng_ro.ns.Ns._process_epa_params")
+    def test__process_flavor_params_with_persistent_root_disk(
+        self,
+        epa_params,
+    ):
+        db = MagicMock(name="database mock")
+
+        kwargs = {
+            "db": db,
+        }
+
+        db.get_one.return_value = {
+            "_id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+            "df": [
+                {
+                    "id": "default-df",
+                    "vdu-profile": [
+                        {"id": "several_volumes-VM", "min-number-of-instances": 1}
+                    ],
+                }
+            ],
+            "id": "several_volumes-vnf",
+            "product-name": "several_volumes-vnf",
+            "vdu": [
+                {
+                    "id": "several_volumes-VM",
+                    "name": "several_volumes-VM",
+                    "sw-image-desc": "ubuntu20.04",
+                    "alternative-sw-image-desc": [
+                        "ubuntu20.04-aws",
+                        "ubuntu20.04-azure",
+                    ],
+                    "virtual-storage-desc": [
+                        "persistent-root-volume",
+                    ],
+                }
+            ],
+            "version": "1.0",
+            "virtual-storage-desc": [
+                {
+                    "id": "persistent-root-volume",
+                    "type-of-storage": "persistent-storage:persistent-storage",
+                    "size-of-storage": "10",
+                },
+            ],
+            "_admin": {
+                "storage": {
+                    "fs": "mongo",
+                    "path": "/app/storage/",
+                },
+                "type": "vnfd",
+            },
+        }
+        expected_result = {
+            "find_params": {
+                "flavor_data": {
+                    "disk": 0,
+                    "ram": 1024,
+                    "vcpus": 2,
+                },
+            },
+            "params": {
+                "flavor_data": {
+                    "disk": 0,
+                    "name": "test",
+                    "ram": 1024,
+                    "vcpus": 2,
+                },
+            },
+        }
+        target_flavor = {
+            "id": "test_id",
+            "name": "test",
+            "storage-gb": "10",
+            "memory-mb": "1024",
+            "vcpu-count": "2",
+        }
+        indata = {
+            "vnf": [
+                {
+                    "vdur": [
+                        {
+                            "vdu-name": "several_volumes-VM",
+                            "ns-flavor-id": "test_id",
+                            "virtual-storages": [
+                                {
+                                    "type-of-storage": "persistent-storage:persistent-storage",
+                                    "size-of-storage": "10",
+                                },
+                            ],
+                        },
+                    ],
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
                 },
             ],
         }
@@ -1656,6 +1834,7 @@ class TestNs(unittest.TestCase):
             indata=indata,
             vim_info=vim_info,
             target_record_id=target_record_id,
+            **kwargs,
         )
 
         self.assertTrue(epa_params.called)
@@ -1666,6 +1845,7 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1696,7 +1876,18 @@ class TestNs(unittest.TestCase):
             "memory-mb": "1024",
             "vcpu-count": "2",
         }
-        indata = {}
+        indata = {
+            "vnf": [
+                {
+                    "vdur": [
+                        {
+                            "ns-flavor-id": "test_id",
+                        },
+                    ],
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+                },
+            ],
+        }
         vim_info = {}
         target_record_id = ""
 
@@ -1719,6 +1910,54 @@ class TestNs(unittest.TestCase):
         self,
         epa_params,
     ):
+        db = MagicMock(name="database mock")
+
+        kwargs = {
+            "db": db,
+        }
+
+        db.get_one.return_value = {
+            "_id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
+            "df": [
+                {
+                    "id": "default-df",
+                    "vdu-profile": [
+                        {"id": "without_volumes-VM", "min-number-of-instances": 1}
+                    ],
+                }
+            ],
+            "id": "without_volumes-vnf",
+            "product-name": "without_volumes-vnf",
+            "vdu": [
+                {
+                    "id": "without_volumes-VM",
+                    "name": "without_volumes-VM",
+                    "sw-image-desc": "ubuntu20.04",
+                    "alternative-sw-image-desc": [
+                        "ubuntu20.04-aws",
+                        "ubuntu20.04-azure",
+                    ],
+                    "virtual-storage-desc": ["root-volume", "ephemeral-volume"],
+                }
+            ],
+            "version": "1.0",
+            "virtual-storage-desc": [
+                {"id": "root-volume", "size-of-storage": "10"},
+                {
+                    "id": "ephemeral-volume",
+                    "type-of-storage": "etsi-nfv-descriptors:ephemeral-storage",
+                    "size-of-storage": "1",
+                },
+            ],
+            "_admin": {
+                "storage": {
+                    "fs": "mongo",
+                    "path": "/app/storage/",
+                },
+                "type": "vnfd",
+            },
+        }
+
         expected_result = {
             "find_params": {
                 "flavor_data": {
@@ -1771,6 +2010,7 @@ class TestNs(unittest.TestCase):
                             ],
                         },
                     ],
+                    "vnfd-id": "ad6356e3-698c-43bf-9901-3aae9e9b9d18",
                 },
             ],
         }
@@ -1786,6 +2026,7 @@ class TestNs(unittest.TestCase):
             indata=indata,
             vim_info=vim_info,
             target_record_id=target_record_id,
+            **kwargs,
         )
 
         self.assertTrue(epa_params.called)
@@ -2398,8 +2639,108 @@ class TestNs(unittest.TestCase):
                 cloud_init_content=cloud_init_content, params=params, context=context
             )
 
-    def test__parse_jinja2(self):
-        pass
+    def test_rendering_jinja2_temp_without_special_characters(self):
+        cloud_init_content = """
+        disk_setup:
+            ephemeral0:
+                table_type: {{type}}
+                layout: True
+                overwrite: {{is_override}}
+        runcmd:
+             - [ ls, -l, / ]
+             - [ sh, -xc, "echo $(date) '{{command}}'" ]
+        """
+        params = {
+            "type": "mbr",
+            "is_override": "False",
+            "command": "; mkdir abc",
+        }
+        context = "cloud-init for VM"
+        expected_result = """
+        disk_setup:
+            ephemeral0:
+                table_type: mbr
+                layout: True
+                overwrite: False
+        runcmd:
+             - [ ls, -l, / ]
+             - [ sh, -xc, "echo $(date) '; mkdir abc'" ]
+        """
+        result = Ns._parse_jinja2(
+            cloud_init_content=cloud_init_content, params=params, context=context
+        )
+        self.assertEqual(result, expected_result)
+
+    def test_rendering_jinja2_temp_with_special_characters(self):
+        cloud_init_content = """
+        disk_setup:
+            ephemeral0:
+                table_type: {{type}}
+                layout: True
+                overwrite: {{is_override}}
+        runcmd:
+             - [ ls, -l, / ]
+             - [ sh, -xc, "echo $(date) '{{command}}'" ]
+        """
+        params = {
+            "type": "mbr",
+            "is_override": "False",
+            "command": "& rm -rf",
+        }
+        context = "cloud-init for VM"
+        expected_result = """
+        disk_setup:
+            ephemeral0:
+                table_type: mbr
+                layout: True
+                overwrite: False
+        runcmd:
+             - [ ls, -l, / ]
+             - [ sh, -xc, "echo $(date) '& rm -rf /'" ]
+        """
+        result = Ns._parse_jinja2(
+            cloud_init_content=cloud_init_content, params=params, context=context
+        )
+        self.assertNotEqual(result, expected_result)
+
+    def test_rendering_jinja2_temp_with_special_characters_autoescape_is_false(self):
+        with patch("osm_ng_ro.ns.Environment") as mock_environment:
+            mock_environment.return_value = Environment(
+                undefined=StrictUndefined,
+                autoescape=select_autoescape(default_for_string=False, default=False),
+            )
+            cloud_init_content = """
+                disk_setup:
+                    ephemeral0:
+                        table_type: {{type}}
+                        layout: True
+                        overwrite: {{is_override}}
+                runcmd:
+                     - [ ls, -l, / ]
+                     - [ sh, -xc, "echo $(date) '{{command}}'" ]
+                """
+            params = {
+                "type": "mbr",
+                "is_override": "False",
+                "command": "& rm -rf /",
+            }
+            context = "cloud-init for VM"
+            expected_result = """
+                disk_setup:
+                    ephemeral0:
+                        table_type: mbr
+                        layout: True
+                        overwrite: False
+                runcmd:
+                     - [ ls, -l, / ]
+                     - [ sh, -xc, "echo $(date) '& rm -rf /'" ]
+                """
+            result = Ns._parse_jinja2(
+                cloud_init_content=cloud_init_content,
+                params=params,
+                context=context,
+            )
+            self.assertEqual(result, expected_result)
 
     def test__process_vdu_params_empty_kargs(self):
         pass
@@ -2756,3 +3097,48 @@ class TestNs(unittest.TestCase):
         )
 
         self.assertDictEqual(task, expected_result)
+
+    @patch("osm_ng_ro.ns.Ns._assign_vim")
+    def test_migrate_task(self, assign_vim):
+        self.ns = Ns()
+        extra_dict = {}
+        vdu_index = "1"
+        action_id = "bb937f49-3870-4169-b758-9732e1ff40f3"
+        nsr_id = "993166fe-723e-4680-ac4b-b1af2541ae31"
+        task_index = 1
+        target_record_id = (
+            "vnfrs:665b4165-ce24-4320-bf19-b9a45bade49f:"
+            "vdur.bb9c43f9-10a2-4569-a8a8-957c3528b6d1"
+        )
+
+        expected_result = {
+            "target_id": "vim:f9f370ac-0d44-41a7-9000-457f2332bc35",
+            "action_id": "bb937f49-3870-4169-b758-9732e1ff40f3",
+            "nsr_id": "993166fe-723e-4680-ac4b-b1af2541ae31",
+            "task_id": "bb937f49-3870-4169-b758-9732e1ff40f3:1",
+            "status": "SCHEDULED",
+            "action": "EXEC",
+            "item": "migrate",
+            "target_record": "vnfrs:665b4165-ce24-4320-bf19-b9a45bade49f:vdur.1",
+            "target_record_id": target_record_id,
+            "params": {
+                "vim_vm_id": "f37b18ef-3caa-4dc9-ab91-15c669b16396",
+                "migrate_host": "migrateToHost",
+            },
+        }
+        vdu = {
+            "id": "bb9c43f9-10a2-4569-a8a8-957c3528b6d1",
+            "vim_info": {
+                "vim:f9f370ac-0d44-41a7-9000-457f2332bc35": {"interfaces": []}
+            },
+        }
+        vnf = {"_id": "665b4165-ce24-4320-bf19-b9a45bade49f"}
+        extra_dict["params"] = {
+            "vim_vm_id": "f37b18ef-3caa-4dc9-ab91-15c669b16396",
+            "migrate_host": "migrateToHost",
+        }
+        task = self.ns.migrate_task(
+            vdu, vnf, vdu_index, action_id, nsr_id, task_index, extra_dict
+        )
+
+        self.assertDictEqual(task, expected_result)