From: Nicki Křížek Date: Tue, 16 Jun 2026 16:23:23 +0000 (+0000) Subject: Move algorithm definitions into a top-level isctest.algorithms module X-Git-Tag: v9.21.24~30^2 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=4d76b7bd9eb6c5b96f43b6f14919b1c762e15e31;p=thirdparty%2Fbind9.git Move algorithm definitions into a top-level isctest.algorithms module The Algorithm type, the per-algorithm constants, and the ALL_ALGORITHMS* lookup tables are general DNSSEC key definitions used across isctest package and the tests. Move them into a dedicated module to separate these from the environment-specific setup that remains in isctest.vars.algorithms. Assisted-by: Claude:claude-opus-4-8 --- diff --git a/bin/tests/system/conftest.py b/bin/tests/system/conftest.py index b9a4943be9c..e0c2a08d660 100644 --- a/bin/tests/system/conftest.py +++ b/bin/tests/system/conftest.py @@ -273,7 +273,7 @@ def control_port(): @pytest.fixture(scope="module") def default_algorithm(): - return isctest.vars.algorithms.Algorithm.default() + return isctest.algorithms.Algorithm.default() @pytest.fixture(scope="module") diff --git a/bin/tests/system/dnssec_py/tests_mixed_ds.py b/bin/tests/system/dnssec_py/tests_mixed_ds.py index a3c9d43845a..57ca84457f5 100644 --- a/bin/tests/system/dnssec_py/tests_mixed_ds.py +++ b/bin/tests/system/dnssec_py/tests_mixed_ds.py @@ -12,8 +12,8 @@ from re import compile as Re from dnssec_py.common import DNSSEC_PY_MARK +from isctest.algorithms import Algorithm from isctest.template import NS2, NS3, zones -from isctest.vars.algorithms import Algorithm from isctest.zone import Zone, configure_root import isctest diff --git a/bin/tests/system/isctest/__init__.py b/bin/tests/system/isctest/__init__.py index 30256087b30..326b77f0d4e 100644 --- a/bin/tests/system/isctest/__init__.py +++ b/bin/tests/system/isctest/__init__.py @@ -10,6 +10,7 @@ # information regarding copyright ownership. from . import ( # pylint: disable=redefined-builtin + algorithms, check, hypothesis, instance, @@ -29,6 +30,7 @@ from . import ( # pylint: disable=redefined-builtin # instead. __all__ = [ + "algorithms", "check", "hypothesis", "instance", diff --git a/bin/tests/system/isctest/algorithms.py b/bin/tests/system/isctest/algorithms.py new file mode 100644 index 00000000000..160282f39a5 --- /dev/null +++ b/bin/tests/system/isctest/algorithms.py @@ -0,0 +1,61 @@ +# Copyright (C) Internet Systems Consortium, Inc. ("ISC") +# +# SPDX-License-Identifier: MPL-2.0 +# +# This Source Code Form is subject to the terms of the Mozilla Public +# License, v. 2.0. If a copy of the MPL was not distributed with this +# file, you can obtain one at https://mozilla.org/MPL/2.0/. +# +# See the COPYRIGHT file distributed with this work for additional +# information regarding copyright ownership. + +from typing import NamedTuple + +import os + + +class Algorithm(NamedTuple): + name: str + number: int + dst: int + bits: int + + @classmethod + def default(cls): + return cls( + os.environ["DEFAULT_ALGORITHM"], + int(os.environ["DEFAULT_ALGORITHM_NUMBER"]), + int(os.environ["DEFAULT_ALGORITHM_DST_NUMBER"]), + int(os.environ["DEFAULT_BITS"]), + ) + + +RSASHA1 = Algorithm("RSASHA1", 5, 5, 2048) +NSEC3RSASHA1 = Algorithm("NSEC3RSASHA1", 7, 7, 2048) +RSASHA256 = Algorithm("RSASHA256", 8, 8, 2048) +RSASHA512 = Algorithm("RSASHA512", 10, 10, 2048) +ECDSAP256SHA256 = Algorithm("ECDSAP256SHA256", 13, 13, 256) +ECDSAP384SHA384 = Algorithm("ECDSAP384SHA384", 14, 14, 384) +ED25519 = Algorithm("ED25519", 15, 15, 256) +ED448 = Algorithm("ED448", 16, 16, 456) +RSASHA256OID = Algorithm("RSASHA256OID", 254, 256, 2048) +RSASHA512OID = Algorithm("RSASHA512OID", 254, 257, 2048) + +ALL_ALGORITHMS = [ + RSASHA1, + NSEC3RSASHA1, + RSASHA256, + RSASHA512, + ECDSAP256SHA256, + ECDSAP384SHA384, + ED25519, + ED448, + RSASHA256OID, + RSASHA512OID, +] + +ALL_ALGORITHMS_BY_NUM = {alg.number: alg for alg in ALL_ALGORITHMS} +# Keyed by the DST identifier rather than the on-wire number: unlike `number` +# (where both private-OID variants collide at 254), `dst` is unique, so this +# map distinguishes RSASHA256OID (256) from RSASHA512OID (257). +ALL_ALGORITHMS_BY_DST = {alg.dst: alg for alg in ALL_ALGORITHMS} diff --git a/bin/tests/system/isctest/kasp.py b/bin/tests/system/isctest/kasp.py index 2c82cce37b5..0bc7bd9b4be 100644 --- a/bin/tests/system/isctest/kasp.py +++ b/bin/tests/system/isctest/kasp.py @@ -29,9 +29,9 @@ import dns.rdatatype import dns.tsig import dns.zone +from isctest.algorithms import ALL_ALGORITHMS_BY_DST, ECDSAP256SHA256, Algorithm from isctest.instance import NamedInstance from isctest.run import EnvCmd -from isctest.vars.algorithms import ALL_ALGORITHMS_BY_DST, ECDSAP256SHA256, Algorithm from isctest.zone import FileZoneKey import isctest.log diff --git a/bin/tests/system/isctest/vars/algorithms.py b/bin/tests/system/isctest/vars/algorithms.py index a0081e0c47c..61c8097f711 100644 --- a/bin/tests/system/isctest/vars/algorithms.py +++ b/bin/tests/system/isctest/vars/algorithms.py @@ -19,6 +19,16 @@ import tempfile import time from .. import log +from ..algorithms import ( + ALL_ALGORITHMS, + ECDSAP256SHA256, + ECDSAP384SHA384, + ED448, + ED25519, + RSASHA256, + RSASHA512, + Algorithm, +) from .basic import BASIC_VARS # Algorithms are selected randomly at runtime from a list of supported @@ -55,22 +65,6 @@ STABLE_PERIOD = 3600 * 3 """number of secs during which algorithm selection remains stable""" -class Algorithm(NamedTuple): - name: str - number: int - dst: int - bits: int - - @classmethod - def default(cls): - return cls( - os.environ["DEFAULT_ALGORITHM"], - int(os.environ["DEFAULT_ALGORITHM_NUMBER"]), - int(os.environ["DEFAULT_ALGORITHM_DST_NUMBER"]), - int(os.environ["DEFAULT_BITS"]), - ) - - class AlgorithmSet(NamedTuple): """Collection of DEFAULT, ALTERNATIVE and DISABLED algorithms""" @@ -86,36 +80,6 @@ class AlgorithmSet(NamedTuple): "disable-algorithms" configuration option.""" -RSASHA1 = Algorithm("RSASHA1", 5, 5, 2048) -NSEC3RSASHA1 = Algorithm("NSEC3RSASHA1", 7, 7, 2048) -RSASHA256 = Algorithm("RSASHA256", 8, 8, 2048) -RSASHA512 = Algorithm("RSASHA512", 10, 10, 2048) -ECDSAP256SHA256 = Algorithm("ECDSAP256SHA256", 13, 13, 256) -ECDSAP384SHA384 = Algorithm("ECDSAP384SHA384", 14, 14, 384) -ED25519 = Algorithm("ED25519", 15, 15, 256) -ED448 = Algorithm("ED448", 16, 16, 456) -RSASHA256OID = Algorithm("RSASHA256OID", 254, 256, 2048) -RSASHA512OID = Algorithm("RSASHA512OID", 254, 257, 2048) - -ALL_ALGORITHMS = [ - RSASHA1, - NSEC3RSASHA1, - RSASHA256, - RSASHA512, - ECDSAP256SHA256, - ECDSAP384SHA384, - ED25519, - ED448, - RSASHA256OID, - RSASHA512OID, -] - -ALL_ALGORITHMS_BY_NUM = {alg.number: alg for alg in ALL_ALGORITHMS} -# Keyed by the DST identifier rather than the on-wire number: unlike `number` -# (where both private-OID variants collide at 254), `dst` is unique, so this -# map distinguishes RSASHA256OID (256) from RSASHA512OID (257). -ALL_ALGORITHMS_BY_DST = {alg.dst: alg for alg in ALL_ALGORITHMS} - ALGORITHM_SETS = { "stable": AlgorithmSet( default=ECDSAP256SHA256, alternative=RSASHA256, disabled=ECDSAP384SHA384 diff --git a/bin/tests/system/isctest/zone.py b/bin/tests/system/isctest/zone.py index 8f5a8866277..359d0f27074 100644 --- a/bin/tests/system/isctest/zone.py +++ b/bin/tests/system/isctest/zone.py @@ -30,10 +30,7 @@ import dns.rdatatype import dns.rrset import dns.zonefile -from .log import debug -from .run import EnvCmd -from .template import NS1, Nameserver, TemplateEngine, TrustAnchor -from .vars.algorithms import ( +from .algorithms import ( ALL_ALGORITHMS_BY_NUM, ECDSAP256SHA256, ECDSAP384SHA384, @@ -41,6 +38,9 @@ from .vars.algorithms import ( ED25519, Algorithm, ) +from .log import debug +from .run import EnvCmd +from .template import NS1, Nameserver, TemplateEngine, TrustAnchor KEYDIR = "keys" DNSKEY_TTL = 3600 diff --git a/bin/tests/system/kasp/tests_kasp.py b/bin/tests/system/kasp/tests_kasp.py index 5f970a66be1..c57807e940c 100644 --- a/bin/tests/system/kasp/tests_kasp.py +++ b/bin/tests/system/kasp/tests_kasp.py @@ -25,9 +25,9 @@ import dns.tsig import dns.update import pytest +from isctest.algorithms import ECDSAP256SHA256, ECDSAP384SHA384, Algorithm from isctest.kasp import KeyProperties, KeyTimingMetadata, SettimeOptions from isctest.util import param -from isctest.vars.algorithms import ECDSAP256SHA256, ECDSAP384SHA384, Algorithm import isctest import isctest.mark diff --git a/bin/tests/system/ksr/tests_ksr.py b/bin/tests/system/ksr/tests_ksr.py index b1e1be907eb..5f54a3361f0 100644 --- a/bin/tests/system/ksr/tests_ksr.py +++ b/bin/tests/system/ksr/tests_ksr.py @@ -18,8 +18,8 @@ import time import pytest +from isctest.algorithms import Algorithm from isctest.kasp import KeyTimingMetadata -from isctest.vars.algorithms import Algorithm from rollover.common import TIMEDELTA import isctest diff --git a/bin/tests/system/migrate2kasp/tests_migrate2kasp.py b/bin/tests/system/migrate2kasp/tests_migrate2kasp.py index 3e4150ee7f6..750eee509b5 100644 --- a/bin/tests/system/migrate2kasp/tests_migrate2kasp.py +++ b/bin/tests/system/migrate2kasp/tests_migrate2kasp.py @@ -15,7 +15,7 @@ import os import pytest -from isctest.vars.algorithms import Algorithm +from isctest.algorithms import Algorithm import isctest diff --git a/bin/tests/system/nsec3/tests_nsec3_change.py b/bin/tests/system/nsec3/tests_nsec3_change.py index b8a8b066e36..564a670d637 100644 --- a/bin/tests/system/nsec3/tests_nsec3_change.py +++ b/bin/tests/system/nsec3/tests_nsec3_change.py @@ -17,7 +17,7 @@ import dns.rdataclass import dns.rdatatype import pytest -from isctest.vars.algorithms import Algorithm +from isctest.algorithms import Algorithm from nsec3.common import NSEC3_MARK, check_nsec3_case import isctest diff --git a/bin/tests/system/nsec3/tests_nsec3_initial.py b/bin/tests/system/nsec3/tests_nsec3_initial.py index d855032bd13..8fb23ee2a2f 100644 --- a/bin/tests/system/nsec3/tests_nsec3_initial.py +++ b/bin/tests/system/nsec3/tests_nsec3_initial.py @@ -17,7 +17,7 @@ import dns.rcode import dns.update import pytest -from isctest.vars.algorithms import RSASHA1, Algorithm +from isctest.algorithms import RSASHA1, Algorithm from nsec3.common import NSEC3_MARK, check_nsec3_case import isctest diff --git a/bin/tests/system/nsec3/tests_nsec3_reconfig.py b/bin/tests/system/nsec3/tests_nsec3_reconfig.py index 1a4ba812f0b..ea3ee8e843a 100644 --- a/bin/tests/system/nsec3/tests_nsec3_reconfig.py +++ b/bin/tests/system/nsec3/tests_nsec3_reconfig.py @@ -18,7 +18,7 @@ import dns.rdataclass import dns.rdatatype import pytest -from isctest.vars.algorithms import RSASHA1, Algorithm +from isctest.algorithms import RSASHA1, Algorithm from nsec3.common import NSEC3_MARK, check_nsec3_case import isctest diff --git a/bin/tests/system/nsec3/tests_nsec3_restart.py b/bin/tests/system/nsec3/tests_nsec3_restart.py index ca6ebef8118..aed7c417812 100644 --- a/bin/tests/system/nsec3/tests_nsec3_restart.py +++ b/bin/tests/system/nsec3/tests_nsec3_restart.py @@ -14,7 +14,7 @@ import os import dns.rdatatype import pytest -from isctest.vars.algorithms import Algorithm +from isctest.algorithms import Algorithm from nsec3.common import NSEC3_MARK, check_nsec3_case, check_nsec3param import isctest diff --git a/bin/tests/system/nsec3/tests_nsec3_retransfer.py b/bin/tests/system/nsec3/tests_nsec3_retransfer.py index 4df768cc00f..bb019d395fb 100644 --- a/bin/tests/system/nsec3/tests_nsec3_retransfer.py +++ b/bin/tests/system/nsec3/tests_nsec3_retransfer.py @@ -16,7 +16,7 @@ import os import dns.rcode import dns.rdatatype -from isctest.vars.algorithms import RSASHA256 +from isctest.algorithms import RSASHA256 from nsec3.common import NSEC3_MARK, check_auth_nsec3, check_nsec3param import isctest diff --git a/bin/tests/system/rollover/setup.py b/bin/tests/system/rollover/setup.py index dc83402069d..97bed7e1e88 100644 --- a/bin/tests/system/rollover/setup.py +++ b/bin/tests/system/rollover/setup.py @@ -13,10 +13,10 @@ from pathlib import Path import shutil +from isctest.algorithms import Algorithm from isctest.kasp import SettimeOptions, private_type_record from isctest.run import EnvCmd from isctest.template import NS2, NS3, TrustAnchor, Zone -from isctest.vars.algorithms import Algorithm import isctest diff --git a/bin/tests/system/rollover/tests_rollover_manual.py b/bin/tests/system/rollover/tests_rollover_manual.py index 71907a0be53..d7e326db9c2 100644 --- a/bin/tests/system/rollover/tests_rollover_manual.py +++ b/bin/tests/system/rollover/tests_rollover_manual.py @@ -11,6 +11,7 @@ from datetime import timedelta +from isctest.algorithms import Algorithm from isctest.kasp import ( Ipub, Iret, @@ -20,7 +21,6 @@ from isctest.kasp import ( ) from isctest.run import EnvCmd from isctest.template import NS3, Zone -from isctest.vars.algorithms import Algorithm from rollover.setup import configure_root, configure_tld, setkeytimes import isctest