|
18 | 18 |
|
19 | 19 | PGTDE::psql($node, 'postgres', 'CREATE EXTENSION IF NOT EXISTS pg_tde;');
|
20 | 20 |
|
21 |
| -PGTDE::psql($node, 'postgres', 'CREATE TABLE test_enc(id SERIAL,k INTEGER,PRIMARY KEY (id)) USING tde_heap;'); |
| 21 | +PGTDE::psql($node, 'postgres', |
| 22 | + 'CREATE TABLE test_enc(id SERIAL,k INTEGER,PRIMARY KEY (id)) USING tde_heap;' |
| 23 | +); |
22 | 24 |
|
23 | 25 | PGTDE::append_to_result_file("-- server restart");
|
24 | 26 | $node->stop();
|
25 | 27 | $rt_value = $node->start();
|
26 | 28 | ok($rt_value == 1, "Restart Server");
|
27 | 29 |
|
28 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_add_database_key_provider_file('file-vault','/tmp/pg_tde_test_keyring.per');"); |
29 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_add_database_key_provider_file('file-2','/tmp/pg_tde_test_keyring_2.per');"); |
30 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_add_global_key_provider_file('file-2','/tmp/pg_tde_test_keyring_2g.per');"); |
31 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_add_global_key_provider_file('file-3','/tmp/pg_tde_test_keyring_3.per');"); |
32 |
| - |
33 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_list_all_database_key_providers();"); |
34 |
| - |
35 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_database_key_provider('test-db-key','file-vault');"); |
36 |
| - |
37 |
| -PGTDE::psql($node, 'postgres', 'CREATE TABLE test_enc(id SERIAL,k INTEGER,PRIMARY KEY (id)) USING tde_heap;'); |
| 30 | +PGTDE::psql($node, 'postgres', |
| 31 | + "SELECT pg_tde_add_database_key_provider_file('file-vault','/tmp/pg_tde_test_keyring.per');" |
| 32 | +); |
| 33 | +PGTDE::psql($node, 'postgres', |
| 34 | + "SELECT pg_tde_add_database_key_provider_file('file-2','/tmp/pg_tde_test_keyring_2.per');" |
| 35 | +); |
| 36 | +PGTDE::psql($node, 'postgres', |
| 37 | + "SELECT pg_tde_add_global_key_provider_file('file-2','/tmp/pg_tde_test_keyring_2g.per');" |
| 38 | +); |
| 39 | +PGTDE::psql($node, 'postgres', |
| 40 | + "SELECT pg_tde_add_global_key_provider_file('file-3','/tmp/pg_tde_test_keyring_3.per');" |
| 41 | +); |
| 42 | + |
| 43 | +PGTDE::psql($node, 'postgres', |
| 44 | + "SELECT pg_tde_list_all_database_key_providers();"); |
| 45 | + |
| 46 | +PGTDE::psql($node, 'postgres', |
| 47 | + "SELECT pg_tde_set_key_using_database_key_provider('test-db-key','file-vault');" |
| 48 | +); |
| 49 | + |
| 50 | +PGTDE::psql($node, 'postgres', |
| 51 | + 'CREATE TABLE test_enc(id SERIAL,k INTEGER,PRIMARY KEY (id)) USING tde_heap;' |
| 52 | +); |
38 | 53 |
|
39 | 54 | PGTDE::psql($node, 'postgres', 'INSERT INTO test_enc (k) VALUES (5),(6);');
|
40 | 55 |
|
41 | 56 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
42 | 57 |
|
43 | 58 | # Rotate key
|
44 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_database_key_provider('rotated-key1');"); |
| 59 | +PGTDE::psql($node, 'postgres', |
| 60 | + "SELECT pg_tde_set_key_using_database_key_provider('rotated-key1');"); |
45 | 61 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
46 | 62 |
|
47 | 63 | PGTDE::append_to_result_file("-- server restart");
|
48 | 64 | $node->stop();
|
49 | 65 | $rt_value = $node->start();
|
50 | 66 | ok($rt_value == 1, "Restart Server");
|
51 | 67 |
|
52 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
53 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
| 68 | +PGTDE::psql($node, 'postgres', |
| 69 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 70 | +); |
| 71 | +PGTDE::psql($node, 'postgres', |
| 72 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 73 | +); |
54 | 74 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
55 | 75 |
|
56 | 76 | # Again rotate key
|
57 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_database_key_provider('rotated-key2','file-2');"); |
| 77 | +PGTDE::psql($node, 'postgres', |
| 78 | + "SELECT pg_tde_set_key_using_database_key_provider('rotated-key2','file-2');" |
| 79 | +); |
58 | 80 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
59 | 81 |
|
60 | 82 | PGTDE::append_to_result_file("-- server restart");
|
61 | 83 | $node->stop();
|
62 | 84 | $rt_value = $node->start();
|
63 | 85 | ok($rt_value == 1, "Restart Server");
|
64 | 86 |
|
65 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
66 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
| 87 | +PGTDE::psql($node, 'postgres', |
| 88 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 89 | +); |
| 90 | +PGTDE::psql($node, 'postgres', |
| 91 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 92 | +); |
67 | 93 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
68 | 94 |
|
69 | 95 | # Again rotate key
|
70 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_global_key_provider('rotated-key', 'file-3', false);"); |
| 96 | +PGTDE::psql($node, 'postgres', |
| 97 | + "SELECT pg_tde_set_key_using_global_key_provider('rotated-key', 'file-3', false);" |
| 98 | +); |
71 | 99 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
72 | 100 |
|
73 | 101 | PGTDE::append_to_result_file("-- server restart");
|
74 | 102 | $node->stop();
|
75 | 103 | $rt_value = $node->start();
|
76 | 104 | ok($rt_value == 1, "Restart Server");
|
77 | 105 |
|
78 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
79 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
| 106 | +PGTDE::psql($node, 'postgres', |
| 107 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 108 | +); |
| 109 | +PGTDE::psql($node, 'postgres', |
| 110 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 111 | +); |
80 | 112 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
81 | 113 |
|
82 | 114 | # TODO: add method to query current info
|
83 | 115 | # And maybe debug tools to show what's in a file keyring?
|
84 | 116 |
|
85 | 117 | # Again rotate key
|
86 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_global_key_provider('rotated-keyX', 'file-2', false);"); |
| 118 | +PGTDE::psql($node, 'postgres', |
| 119 | + "SELECT pg_tde_set_key_using_global_key_provider('rotated-keyX', 'file-2', false);" |
| 120 | +); |
87 | 121 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
88 | 122 |
|
89 | 123 | PGTDE::append_to_result_file("-- server restart");
|
90 | 124 | $node->stop();
|
91 | 125 | $rt_value = $node->start();
|
92 | 126 | ok($rt_value == 1, "Restart Server");
|
93 | 127 |
|
94 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
95 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
| 128 | +PGTDE::psql($node, 'postgres', |
| 129 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 130 | +); |
| 131 | +PGTDE::psql($node, 'postgres', |
| 132 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 133 | +); |
96 | 134 | PGTDE::psql($node, 'postgres', 'SELECT * FROM test_enc ORDER BY id ASC;');
|
97 | 135 |
|
98 |
| -PGTDE::psql($node, 'postgres', 'ALTER SYSTEM SET pg_tde.inherit_global_providers = OFF;'); |
| 136 | +PGTDE::psql($node, 'postgres', |
| 137 | + 'ALTER SYSTEM SET pg_tde.inherit_global_providers = OFF;'); |
99 | 138 |
|
100 | 139 | # Things still work after a restart
|
101 | 140 | PGTDE::append_to_result_file("-- server restart");
|
|
104 | 143 | ok($rt_value == 1, "Restart Server");
|
105 | 144 |
|
106 | 145 | # But now can't be changed to another global provider
|
107 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_global_key_provider('rotated-keyX2', 'file-2', false);"); |
108 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
109 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
110 |
| - |
111 |
| -PGTDE::psql($node, 'postgres', "SELECT pg_tde_set_key_using_database_key_provider('rotated-key2','file-2');"); |
112 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();"); |
113 |
| -PGTDE::psql($node, 'postgres', "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();"); |
| 146 | +PGTDE::psql($node, 'postgres', |
| 147 | + "SELECT pg_tde_set_key_using_global_key_provider('rotated-keyX2', 'file-2', false);" |
| 148 | +); |
| 149 | +PGTDE::psql($node, 'postgres', |
| 150 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 151 | +); |
| 152 | +PGTDE::psql($node, 'postgres', |
| 153 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 154 | +); |
| 155 | + |
| 156 | +PGTDE::psql($node, 'postgres', |
| 157 | + "SELECT pg_tde_set_key_using_database_key_provider('rotated-key2','file-2');" |
| 158 | +); |
| 159 | +PGTDE::psql($node, 'postgres', |
| 160 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_key_info();" |
| 161 | +); |
| 162 | +PGTDE::psql($node, 'postgres', |
| 163 | + "SELECT key_provider_id, key_provider_name, key_name FROM pg_tde_server_key_info();" |
| 164 | +); |
114 | 165 |
|
115 | 166 | PGTDE::psql($node, 'postgres', 'DROP TABLE test_enc;');
|
116 | 167 |
|
117 |
| -PGTDE::psql($node, 'postgres', 'ALTER SYSTEM RESET pg_tde.inherit_global_providers;'); |
| 168 | +PGTDE::psql($node, 'postgres', |
| 169 | + 'ALTER SYSTEM RESET pg_tde.inherit_global_providers;'); |
118 | 170 |
|
119 | 171 | PGTDE::append_to_result_file("-- server restart");
|
120 | 172 | $node->stop();
|
|
128 | 180 | # Compare the expected and out file
|
129 | 181 | my $compare = PGTDE->compare_results();
|
130 | 182 |
|
131 |
| -is($compare,0,"Compare Files: $PGTDE::expected_filename_with_path and $PGTDE::out_filename_with_path files."); |
| 183 | +is($compare, 0, |
| 184 | + "Compare Files: $PGTDE::expected_filename_with_path and $PGTDE::out_filename_with_path files." |
| 185 | +); |
132 | 186 |
|
133 | 187 | done_testing();
|
0 commit comments