Skip to content

Commit f38d2ba

Browse files
committed
test: ensure role gathers the facts it uses by having test clear_facts before include_role
The role gathers the facts it uses. For example, if the user uses `ANSIBLE_GATHERING=explicit`, the role uses the `setup` module with the facts and subsets it requires. This change allows us to test this. Before every role invocation, the test will use `meta: clear_facts` so that the role starts with no facts. Create a task file tests/tasks/run_role_with_clear_facts.yml to do the tasks to clear the facts and run the role. Note that this means we don't need to use `gather_facts` for the tests. Some vars defined using `ansible_facts` have been changed to be defined with `set_fact` instead. This is because of the fact that `vars` are lazily evaluated - the var might be referenced when the facts have been cleared, and will issue an error like `ansible_facts["distribution"] is undefined`. This is typically done for blocks that have a `when` condition that uses `ansible_facts` and the block has a role invocation using run_role_with_clear_facts.yml These have been rewritten to define the `when` condition using `set_fact`. This is because the `when` condition is evaluated every time a task is invoked in the block, and if the facts are cleared, this will raise an undefined variable error. Signed-off-by: Rich Megginson <rmeggins@redhat.com>
1 parent 9015de3 commit f38d2ba

10 files changed

Lines changed: 64 additions & 26 deletions
Lines changed: 37 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,37 @@
1+
---
2+
# Task file: clear_facts, run linux-system-roles.vpn.
3+
# Include this with include_tasks or import_tasks
4+
# Input:
5+
# - __sr_tasks_from: tasks_from to run - same as tasks_from in include_role
6+
# - __sr_public: export private vars from role - same as public in include_role
7+
# - __sr_failed_when: set to false to ignore role errors - same as failed_when in include_role
8+
- name: Clear facts
9+
meta: clear_facts
10+
11+
# note that you can use failed_when with import_role but not with include_role
12+
# so this simulates the __sr_failed_when false case
13+
# Q: Why do we need a separate task to run the role normally? Why not just
14+
# run the role in the block and rethrow the error in the rescue block?
15+
# A: Because you cannot rethrow the error in exactly the same way as the role does.
16+
# It might be possible to exactly reconstruct ansible_failed_result but it's not worth the effort.
17+
- name: Run the role with __sr_failed_when false
18+
when:
19+
- __sr_failed_when is defined
20+
- not __sr_failed_when
21+
block:
22+
- name: Run the role
23+
include_role:
24+
name: linux-system-roles.vpn
25+
tasks_from: "{{ __sr_tasks_from | default('main') }}"
26+
public: "{{ __sr_public | default(false) }}"
27+
rescue:
28+
- name: Ignore the failure when __sr_failed_when is false
29+
debug:
30+
msg: Ignoring failure when __sr_failed_when is false
31+
32+
- name: Run the role normally
33+
include_role:
34+
name: linux-system-roles.vpn
35+
tasks_from: "{{ __sr_tasks_from | default('main') }}"
36+
public: "{{ __sr_public | default(false) }}"
37+
when: __sr_failed_when | d(true)

tests/tests_default.yml

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,11 +1,13 @@
11
---
22
- name: Ensure that the role runs with default parameters
33
hosts: all
4-
roles:
5-
- linux-system-roles.vpn
6-
post_tasks:
4+
tasks:
5+
- name: Run the VPN role
6+
include_tasks: tasks/run_role_with_clear_facts.yml
7+
vars:
8+
__sr_public: true
9+
710
- name: Cleanup
811
include_tasks: tasks/cleanup.yml
912
tags:
1013
- tests::cleanup
11-
gather_facts: false

tests/tests_defaults_vars.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -3,9 +3,9 @@
33
hosts: all
44
tasks:
55
- name: Run the role
6-
include_role:
7-
name: linux-system-roles.vpn
8-
public: true
6+
include_tasks: tasks/run_role_with_clear_facts.yml
7+
vars:
8+
__sr_public: true
99

1010
- name: Assert that the role declares all parameters in defaults
1111
assert:

tests/tests_host_to_host_cert.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -47,9 +47,9 @@
4747
__vpn_main_certname: "{{ vpn_connections[0]['hosts'][__vpn_main_hostname]['cert_name'] }}"
4848

4949
- name: Use vpn role
50-
include_role:
51-
name: linux-system-roles.vpn
52-
public: true
50+
include_tasks: tasks/run_role_with_clear_facts.yml
51+
vars:
52+
__sr_public: true
5353

5454
- name: Assert file existence
5555
include_tasks: tasks/assert_conf_secrets_files_exist.yml

tests/tests_host_to_host_psk.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -21,9 +21,9 @@
2121
auto: start
2222

2323
- name: Use vpn role
24-
include_role:
25-
name: linux-system-roles.vpn
26-
public: true
24+
include_tasks: tasks/run_role_with_clear_facts.yml
25+
vars:
26+
__sr_public: true
2727

2828
- name: Assert file existence
2929
include_tasks: tasks/assert_conf_secrets_files_exist.yml

tests/tests_host_to_host_psk_custom.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -58,9 +58,9 @@
5858
vpn_connections: "{{ __new_vpn_connections }}"
5959

6060
- name: Use vpn role
61-
include_role:
62-
name: linux-system-roles.vpn
63-
public: true
61+
include_tasks: tasks/run_role_with_clear_facts.yml
62+
vars:
63+
__sr_public: true
6464

6565
- name: Assert file existence
6666
include_tasks: tasks/assert_conf_secrets_files_exist.yml

tests/tests_host_to_unmanaged_host.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -26,9 +26,9 @@
2626
vpn_connections: "{{ __new_vpn_connections }}"
2727

2828
- name: Use vpn role
29-
include_role:
30-
name: linux-system-roles.vpn
31-
public: true
29+
include_tasks: tasks/run_role_with_clear_facts.yml
30+
vars:
31+
__sr_public: true
3232

3333
- name: Stat unmanaged host conf file path
3434
stat:

tests/tests_include_vars_from_parent.yml

Lines changed: 0 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,7 +1,6 @@
11
---
22
- name: Test role include variable override
33
hosts: all
4-
gather_facts: true
54
tasks:
65
- name: Create var file in caller that can override the one in called role
76
delegate_to: localhost

tests/tests_mesh_cert.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -43,9 +43,9 @@
4343
cert_name: "{{ __vpn_main_certname }}"
4444

4545
- name: Use vpn role
46-
include_role:
47-
name: linux-system-roles.vpn
48-
public: true
46+
include_tasks: tasks/run_role_with_clear_facts.yml
47+
vars:
48+
__sr_public: true
4949
ignore_errors: true # noqa ignore-errors
5050

5151
- name: Flush handlers

tests/tests_subnet_to_subnet.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -41,9 +41,9 @@
4141
vpn_connections: "{{ __new_vpn_connections }}"
4242

4343
- name: Use vpn role
44-
include_role:
45-
name: linux-system-roles.vpn
46-
public: true
44+
include_tasks: tasks/run_role_with_clear_facts.yml
45+
vars:
46+
__sr_public: true
4747

4848
- name: Assert file existence
4949
include_tasks: tasks/assert_conf_secrets_files_exist.yml

0 commit comments

Comments
 (0)