Skip to content

test rewrite: legacy intg test_pam_responder.py - first batch - #9004

Open
danlavu wants to merge 2 commits into
SSSD:masterfrom
danlavu:rewrite-test_pam_responder.py1
Open

test rewrite: legacy intg test_pam_responder.py - first batch#9004
danlavu wants to merge 2 commits into
SSSD:masterfrom
danlavu:rewrite-test_pam_responder.py1

Conversation

@danlavu

@danlavu danlavu commented Jul 24, 2026

Copy link
Copy Markdown
Contributor

Port sssd/src/tests/intg/test_pam_responder.py to test_smartcard.py, test_authentication.py

  • test_smartcard__login_fails_when_wrong_pin_is_entered
  • test_smartcard__login_fails_when_card_is_not_mapped
  • test_smartcard__cert_auth_limited_to_allowed_pam_services
  • test_smartcard__login_succeeds_when_cert_auth_required
  • test_smartcard__login_fails_when_cert_auth_required_without_card
  • test_authentication__custom_password_prompt_is_shown_at_login

Peeling out the reviewed test cases into it's own PR, from #8873

Depends on the following test-framework PR SSSD/sssd-test-framework#262

Model used: Claude Sonnet 4.6

Comment thread src/tests/system/tests/test_authentication.py Fixed
Comment thread src/tests/system/tests/test_authentication.py Fixed
Comment thread src/tests/system/tests/test_authentication.py Fixed
@danlavu
danlavu force-pushed the rewrite-test_pam_responder.py1 branch 2 times, most recently from 5245b03 to a4d6875 Compare July 28, 2026 19:34
@danlavu
danlavu force-pushed the rewrite-test_pam_responder.py1 branch 2 times, most recently from 40157ea to cfc5634 Compare August 6, 2026 18:56
result.rc == 0
), f"vlock smartcard authentication failed: rc={result.rc}, stdout={result.stdout}, stderr={result.stderr}"

@pytest.mark.importance("medium")

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hey Dan,
the five new test functions from here looks like they're accidentally nested inside test_smartcard__unlock_console_with_vlock, they just need to be dedented to module level so pytest can pick them up.

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Yes, that was a mess. I must have accidentally rebased in the wrong direction or something similar.

I also moved the vlock authentication method from the test into the framework.

@danlavu
danlavu force-pushed the rewrite-test_pam_responder.py1 branch 6 times, most recently from 1ad7a8d to bfccc32 Compare August 13, 2026 19:08
Comment thread src/tests/system/tests/test_smartcard.py
Port sssd/src/tests/intg/test_pam_responder.py to test_smartcard.py,
test_authentication.py

- test_smartcard__login_fails_when_wrong_pin_is_entered
- test_smartcard__login_fails_when_card_is_not_mapped
- test_smartcard__cert_auth_limited_to_allowed_pam_services
- test_smartcard__login_succeeds_when_cert_auth_required
- test_smartcard__login_fails_when_cert_auth_required_without_card
- test_authentication__custom_password_prompt_is_shown_at_login

Peeling out the reviewed test cases into it's own PR, from
SSSD#8873

AI: Claude Sonnet 4.6
Co-authored-by: Cursor <cursoragent@cursor.com>
@danlavu
danlavu force-pushed the rewrite-test_pam_responder.py1 branch from bfccc32 to 31951eb Compare August 14, 2026 15:40


@pytest.mark.parametrize('simple_pam_cert_auth', ['proxy_password'], indirect=True)
def test_sc_proxy_password_fallback(simple_pam_cert_auth, env_for_sssctl):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

this PR does not contain a replacement for this test.

bye,
Sumit

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added it to #9028

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

thank you, nevertheless, can you remove the removal of the related intg tests from this PR?

bye,
Sumit

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Done.


@pytest.mark.parametrize('simple_pam_cert_auth', ['proxy_password_with_sc'],
indirect=True)
def test_sc_proxy_no_password_fallback(simple_pam_cert_auth, env_for_sssctl):

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Hi,

this PR does not contain a replacement for this test.

bye,
Sumit

Copy link
Copy Markdown
Contributor Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Added it to #9028

Replace inline expect script in test_smartcard__unlock_console_with_vlock
with client.auth.su.vlock_smartcard(), moving the logic into the
test framework.

Co-authored-by: Cursor <cursoragent@cursor.com>
@danlavu
danlavu force-pushed the rewrite-test_pam_responder.py1 branch from 31951eb to 4e3755e Compare August 19, 2026 13:42
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants