<style>
/* Changing the layout to use less space for mobiles */
@media screen and (max-device-width: 480px), screen and (-webkit-min-device-pixel-ratio: 2) {
#email-body { min-width: 30em !important; }
#email-page { padding: 8px !important; }
#email-banner { padding: 8px 8px 0 8px !important; }
#email-avatar { margin: 1px 8px 8px 0 !important; padding: 0 !important; }
#email-fields { padding: 0 8px 8px 8px !important; }
#email-gutter { width: 0 !important; }
}
</style>
<div id="email-body">
<table id="email-wrap" align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#f0f0f0;color:#000000;width:100%;">
<tr valign="top">
<td id="email-page" style="padding:16px !important;">
<table align="center" border="0" cellpadding="0" cellspacing="0" style="background-color:#ffffff;border:1px solid #bbbbbb;color:#000000;width:100%;">
<tr valign="top">
<td bgcolor="#ffffff" style="background-color:#ffffff;color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;line-height:1;"><img src="https://shibboleth.net/images/shib_240x83.png" alt="" style="vertical-align:top;" /></td>
</tr><tr valign="top">
<td id="email-banner" style="padding:32px 32px 0 32px;">
<table align="left" border="0" cellpadding="0" cellspacing="0" width="100%" style="width:100%;">
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;padding:0;">
<img id="email-avatar" src="https://issues.shibboleth.net/jira/secure/useravatar?avatarId=10202" alt="" height="48" width="48" border="0" align="left" style="padding:0;margin: 0 16px 16px 0;" />
<div id="email-action" style="padding: 0 0 8px 0;font-size:12px;line-height:18px;">
<a class="user-hover" rel="vtsji@idp.protectnetwork.org" id="email_vtsji@idp.protectnetwork.org" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vtsji%40idp.protectnetwork.org" style="color:#326ca6;">vtsji@idp.protectnetwork.org</a>
created <img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> <a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/SSPCPP-589'>SSPCPP-589</a>
</div>
<div id="email-summary" style="font-size:16px;line-height:20px;padding:2px 0 16px 0;">
<a style='color:#326ca6;text-decoration:none;' href='https://issues.shibboleth.net/jira/browse/SSPCPP-589'><strong>Relative paths in Shibboleth XML catalogs are resolved against /usr/share/xml/opensaml</strong></a>
</div>
</td>
</tr>
</table>
</td>
</tr>
<tr valign="top">
<td id="email-fields" style="padding:0 32px 32px 32px;">
<table border="0" cellpadding="0" cellspacing="0" style="padding:0;text-align:left;width:100%;" width="100%">
<tr valign="top">
<td id="email-gutter" style="width:64px;white-space:nowrap;"></td>
<td>
<table border="0" cellpadding="0" cellspacing="0" width="100%">
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Issue Type:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<img src="https://issues.shibboleth.net/jira/images/icons/issuetypes/bug.png" height="16" width="16" border="0" align="absmiddle" alt="Bug"> Bug
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Affects Versions:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
2.5.2 </td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Assignee:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a class="user-hover" rel="cantor.2@osu.edu" id="email_cantor.2@osu.edu" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=cantor.2%40osu.edu" style="color:#326ca6;">Scott Cantor</a>
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Components:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
Configuration </td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Created:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
25/Jul/13 5:22 AM
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Description:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<p style='margin-top:0;margin-bottom:10px;'>I'm trying to write some automated test cases using cxxtest for some extra handlers that I wrote for Shibboleth. This is working out well so far, but I'm now at the point where I would like to spin up a complete Shibboleth instance, much in the same way as shibd does.</p>
<p style='margin-top:0;margin-bottom:10px;'>My folder structure looks something like this:</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
shibsp/
shibd/
shibsptest/
resources/
test1/
etc/
share/
<span class="code-keyword">var</span>/
test2/
etc/
share/
<span class="code-keyword">var</span>/
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>The idea being that each folder <tt>test1</tt>, <tt>test2</tt> etc. serves as the "installation root" for the Shibboleth instance for that test.</p>
<p style='margin-top:0;margin-bottom:10px;'>The problem I'm running into is that I can't get Shibboleth to use relative paths in its XML catalog. I need to use relative paths in the Shibboleth catalog because these test cases will be checked in to source control and could end up anywhere on disk.</p>
<p style='margin-top:0;margin-bottom:10px;'>I know from reading the source code that a relative path to a catalog file, as well as relative paths inside the catalog files, are resolved using XMLTooling's PathResolver.</p>
<p style='margin-top:0;margin-bottom:10px;'>So what I'm trying to do is to:</p>
<ol>
        <li>Set the installation prefix to <tt>/absolute/path/to/shibsptest/resources/test1</tt> (I can get this absolute path dynamically in the code)</li>
        <li>Set <tt>SHIBSP_XMLDIR</tt> to <tt>share/xml</tt></li>
        <li>Specify the location of the Shibboleth catalog file as just <tt>catalog.xml</tt> in <tt>SHIBSP_SCHEMAS</tt>, while still using absolute paths to the OpenSAML and XMLTooling catalogs, and</li>
        <li>Therefore hopefully be able to use relative paths in <tt>share/xml/shibboleth/catalog.xml</tt>, like this:</li>
</ol>
<div class="code panel" style="border-width: 1px;"><div class="codeHeader panelHeader" style="border-bottom-width: 1px;"><b>shibboleth/catalog.xml</b></div><div class="codeContent panelContent">
<pre class="code-java">
<?xml version=<span class="code-quote">"1.0"</span> encoding=<span class="code-quote">"UTF-8"</span>?>
<catalog xmlns=<span class="code-quote">"urn:oasis:names:tc:entity:xmlns:xml:catalog"</span>>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:metadata:1.0"</span> uri=<span class="code-quote">"shibboleth-metadata-1.0.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:<span class="code-keyword">native</span>:sp:config"</span> uri=<span class="code-quote">"shibboleth-2.0-<span class="code-keyword">native</span>-sp-config.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:<span class="code-keyword">native</span>:sp:protocols"</span> uri=<span class="code-quote">"shibboleth-2.0-<span class="code-keyword">native</span>-sp-protocols.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:sp:notify"</span> uri=<span class="code-quote">"shibboleth-2.0-sp-notify.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:afp"</span> uri=<span class="code-quote">"shibboleth-2.0-afp.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:afp:mf:basic"</span> uri=<span class="code-quote">"shibboleth-2.0-afp-mf-basic.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:afp:mf:saml"</span> uri=<span class="code-quote">"shibboleth-2.0-afp-mf-saml.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:2.0:attribute-map"</span> uri=<span class="code-quote">"shibboleth-2.0-attribute-map.xsd"</span>/>
<system systemId=<span class="code-quote">"urn:mace:shibboleth:1.0"</span> uri=<span class="code-quote">"shibboleth.xsd"</span>/>
<system systemId=<span class="code-quote">"http:<span class="code-comment">//schemas.xmlsoap.org/ws/2005/02/trust"</span> uri=<span class="code-quote">"WS-Trust.xsd"</span>/>
</span></catalog>
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>To be clear, the issue is only with loading the Shibboleth catalog file; I can get absolute paths to the catalogs for OpenSAML and XMLTooling from the build system, and the paths inside both of those are also all absolute paths (I know from stepping through the code with a debugger that these catalogs load fine).</p>
<p style='margin-top:0;margin-bottom:10px;'>I.e., my <tt>SHIBSP_SCHEMAS</tt> looks like this:</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
/absolute/path/to/share/xml/xmltooling/catalog.xml:
/absolute/path/to/share/xml/opensaml/saml20-catalog.xml:
/absolute/path/to/share/xml/opensaml/saml11-catalog.xml:
catalog.xml
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>On startup though, it resolves the relative <tt>catalog.xml</tt> path to <tt>/usr/share/xml/opensaml/catalog.xml</tt>. Additionally, if I temporarily hardcode the absolute path to the Shibboleth <tt>catalog.xml</tt> and try again, it's doing the same thing for all of the relative paths inside the catalog file.</p>
<p style='margin-top:0;margin-bottom:10px;'>Stepping through the code, the reason seems to be that the catalog loading is done before XMLTooling's PathResolver is configured with the Shibboleth default prefix and package name, but after initialization of the OpenSAML library:</p>
<div class="code panel" style="border-width: 1px;"><div class="codeContent panelContent">
<pre class="code-java">
<span class="code-keyword">if</span> (!SAMLConfig::getConfig().init()) {
log.fatal(<span class="code-quote">"failed to initialize OpenSAML library"</span>);
<span class="code-keyword">return</span> <span class="code-keyword">false</span>;
}
<span class="code-comment">// ...
</span><span class="code-keyword">if</span> (!catalog_path)
catalog_path = getenv(<span class="code-quote">"SHIBSP_SCHEMAS"</span>);
<span class="code-keyword">if</span> (!catalog_path || !*catalog_path)
catalog_path = SHIBSP_SCHEMAS;
<span class="code-keyword">if</span> (!XMLToolingConfig::getConfig().getValidatingParser().loadCatalogs(catalog_path)) {
log.warn(<span class="code-quote">"failed to load schema catalogs into validating parser"</span>);
}
PathResolver* pr = XMLToolingConfig::getConfig().getPathResolver();
pr->setDefaultPackageName(PACKAGE_NAME);
pr->setDefaultPrefix(inst_prefix2.c_str());
<span class="code-comment">// ...</span>
</pre>
</div></div>
<p style='margin-top:0;margin-bottom:10px;'>What ends up happening is that the SAMLConfig sets the package name in the PathResolver to "opensaml", and leaves everything else at the defaults from the PathResolver constructor. Because <tt>loadCatalogs()</tt> then reuses that same PathResolver instance, the result is that it's resolving relative paths to XML files to <tt>/usr/share/xml/opensaml</tt>. </p>
<p style='margin-top:0;margin-bottom:10px;'>I would've expected it to resolve according to the settings configured for Shibboleth using <tt>SHIBSP_PREFIX</tt>, <tt>SHIBSP_XMLDIR</tt> etc. Maybe the fix is to load the catalogs only after the PathResolver is configured according to the Shibboleth settings?</p>
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Project:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a style="color:#326ca6;" href="https://issues.shibboleth.net/jira/browse/SSPCPP">Shibboleth SP - C++</a>
</td>
</tr> <tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Labels:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
catalog
xml
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Priority:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<img src="https://issues.shibboleth.net/jira/images/icons/priorities/major.png" height="16" width="16" border="0" align="absmiddle" alt="Major"> Major
</td>
</tr>
<tr valign="top">
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 10px 10px 0;white-space:nowrap;">
<strong style="font-weight:normal;color:#505050;">Reporter:</strong>
</td>
<td style="color:#000000;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:12px;padding:0 0 10px 0;width:100%;">
<a class="user-hover" rel="vtsji@idp.protectnetwork.org" id="email_vtsji@idp.protectnetwork.org" href="https://issues.shibboleth.net/jira/secure/ViewProfile.jspa?name=vtsji%40idp.protectnetwork.org" style="color:#326ca6;">vtsji@idp.protectnetwork.org</a>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td>
</tr>
</table>
</td><!-- End #email-page -->
</tr>
<tr valign="top">
<td style="color:#505050;font-family:Arial,FreeSans,Helvetica,sans-serif;font-size:10px;line-height:14px;padding: 0 16px 16px 16px;text-align:center;">
This message is automatically generated by JIRA.<br />
If you think it was sent incorrectly, please contact your JIRA administrators<br />
For more information on JIRA, see: <a style='color:#326ca6;' href='http://www.atlassian.com/software/jira'>http://www.atlassian.com/software/jira</a>
</td>
</tr>
</table><!-- End #email-wrap -->
</div><!-- End #email-body -->