1 #! /usr/bin/ksh -p
   2 #
   3 # CDDL HEADER START
   4 #
   5 # The contents of this file are subject to the terms of the
   6 # Common Development and Distribution License (the "License").
   7 # You may not use this file except in compliance with the License.
   8 #
   9 # You can obtain a copy of the license at usr/src/OPENSOLARIS.LICENSE
  10 # or http://www.opensolaris.org/os/licensing.
  11 # See the License for the specific language governing permissions
  12 # and limitations under the License.
  13 #
  14 # When distributing Covered Code, include this CDDL HEADER in each
  15 # file and include the License file at usr/src/OPENSOLARIS.LICENSE.
  16 # If applicable, add the following below this CDDL HEADER, with the
  17 # fields enclosed by brackets "[]" replaced with your own identifying
  18 # information: Portions Copyright [yyyy] [name of copyright owner]
  19 #
  20 # CDDL HEADER END
  21 #
  22 
  23 #
  24 # Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
  25 # Use is subject to license terms.
  26 #
  27 
  28 #
  29 # Copyright (c) 2013 by Delphix. All rights reserved.
  30 #
  31 
  32 . $STF_SUITE/include/libtest.shlib
  33 
  34 #
  35 # DESCRIPTION:
  36 #
  37 # The RBAC profile "ZFS Storage Management" works
  38 #
  39 # STRATEGY:
  40 #       (create)
  41 #       1. As a normal user, try to create a pool - which should fail.
  42 #       2. Assign "ZFS Storage Management" profile, try to create pool again,
  43 #          which should succeed.
  44 #
  45 #       (works well with other ZFS profile tests)
  46 #       3. Attempt to create a ZFS filesystem, which should fail.
  47 #       4. Add the "ZFS File System Management" profile, attempt to create a FS
  48 #          which should succeed.
  49 #
  50 #       (destroy)
  51 #       5. Remove the FS profile, then attempt to destroy the pool, which
  52 #          should succeed.
  53 #       6. Remove the Storage profile, then attempt to recreate the pool, which
  54 #          should fail.
  55 #
  56 
  57 # We can only run this in the global zone
  58 verify_runnable "global"
  59 
  60 log_assert "The RBAC profile \"ZFS Storage Management\" works"
  61 
  62 ZFS_USER=$($CAT /tmp/zfs-privs-test-user.txt)
  63 
  64 # the user shouldn't be able to do anything initially
  65 log_mustnot $SU $ZFS_USER -c "$ZPOOL create $TESTPOOL $DISKS"
  66 log_mustnot $SU $ZFS_USER -c "$PFEXEC $ZPOOL create $TESTPOOL $DISKS"
  67 
  68 # the first time we assign the profile, we insist it should work
  69 log_must $USERMOD -P "ZFS Storage Management" $ZFS_USER
  70 log_must $SU $ZFS_USER -c "$PFEXEC $ZPOOL create -f $TESTPOOL $DISKS"
  71 
  72 # ensure the user can't create a filesystem with this profile
  73 log_mustnot $SU $ZFS_USER -c "$ZFS create $TESTPOOL/fs"
  74 
  75 # add ZFS File System Management profile, and try to create a fs
  76 log_must $USERMOD -P "ZFS File System Management" $ZFS_USER
  77 log_must $SU $ZFS_USER -c "$PFEXEC $ZFS create $TESTPOOL/fs"
  78 
  79 # revoke File System Management profile
  80 $USERMOD -P, $ZFS_USER
  81 $USERMOD -P "ZFS Storage Management" $ZFS_USER
  82 
  83 # ensure the user can destroy pools
  84 log_mustnot $SU $ZFS_USER -c "$ZPOOL destroy $TESTPOOL"
  85 log_must $SU $ZFS_USER -c "$PFEXEC $ZPOOL destroy $TESTPOOL"
  86 
  87 # revoke Storage Management profile
  88 $USERMOD -P, $ZFS_USER
  89 log_mustnot $SU $ZFS_USER -c "$PFEXEC $ZPOOL create -f $TESTPOOL $DISKS"
  90 
  91 log_pass "The RBAC profile \"ZFS Storage Management\" works"