Firefox/Stub Attribution/Test Plan: Difference between revisions

From MozillaWiki
Jump to navigation Jump to search
No edit summary
Line 1: Line 1:
= Stub Attribution Test Plan =
= Stub Attribution Test Plan =


= Dependencies (tools/systems): =
== Dependencies (tools/systems): ==
* Firefox client code (Stub Installer)
* Firefox client code (Stub Installer)
* [https://github.com/mozilla-services/go-bouncer Bouncer]
* [https://github.com/mozilla-services/go-bouncer Bouncer]
Line 13: Line 13:
** Caveat: Telemetry data lags 3 weeks, even after the switches have been flipped
** Caveat: Telemetry data lags 3 weeks, even after the switches have been flipped


= Acceptance Criteria =
== Acceptance Criteria ==
In order to begin testing, the following are needed:
In order to begin testing, the following are needed:
<bugzilla>
<bugzilla>
Line 26: Line 26:
# production-ready [https://bugzilla.mozilla.org/show_bug.cgi?id=1273940 stubdownloader.prod.mozaws.net] service/instance
# production-ready [https://bugzilla.mozilla.org/show_bug.cgi?id=1273940 stubdownloader.prod.mozaws.net] service/instance


= Open Issues =
== Open Issues ==


= Questions: =
== Questions: ==
# How (or can we even?) establish a reasonable performance metric around downloading the stub installer, currently?
# How (or can we even?) establish a reasonable performance metric around downloading the stub installer, currently?
## ...so we can measure against this baseline when we test the dynamic vs. cached-downloads Stub-Attribution Service
## ...so we can measure against this baseline when we test the dynamic vs. cached-downloads Stub-Attribution Service
Line 59: Line 59:
## Similarly, what about the a) install stub w/attribution b) upgrade to a later version of Firefox case?
## Similarly, what about the a) install stub w/attribution b) upgrade to a later version of Firefox case?


= Testing Approaches =
== Testing Approaches ==


== Manual Tests: ==
=== Manual Tests: ===
# Positive (happy-path) Tests:
# Positive (happy-path) Tests:
## Do Not Track disabled
## Do Not Track disabled
Line 70: Line 70:
##* Verify (how?) that upon successful installation, the stub installer sends a "success!" ping with the same stub_attcode param/value
##* Verify (how?) that upon successful installation, the stub installer sends a "success!" ping with the same stub_attcode param/value


== Regression Testing ==
=== Regression Testing ===
* All browsers available on Windows XP/Vista (test IE 6, IE 7, Chrome) except for Firefox should still get the SHA-1 stub installer
* All browsers available on Windows XP/Vista (test IE 6, IE 7, Chrome) except for Firefox should still get the SHA-1 stub installer


== Negative Testing ==
=== Negative Testing ===
# Ensure other installers/binaries '''don't''' have/pass on the URL param/stub code
# Ensure other installers/binaries '''don't''' have/pass on the URL param/stub code
## e.g. Mac, Linux, full Firefox for Windows installers
## e.g. Mac, Linux, full Firefox for Windows installers


== Performance Testing ==
=== Performance Testing ===


== Load/Soak Tests ==
=== Load/Soak Tests ===
* Against Bouncer
* Against Bouncer
* Against Stub Downloader service
* Against Stub Downloader service
Line 88: Line 88:
* Against Mozilla.org?
* Against Mozilla.org?


== Fuzz/Security Testing ==
=== Fuzz/Security Testing ===
* Purpose:
* Purpose:
** Surface potential incorrectly-handled errors (tracebacks/HTTP 5xx, etc.) and potential security issues
** Surface potential incorrectly-handled errors (tracebacks/HTTP 5xx, etc.) and potential security issues
Line 96: Line 96:
** Against Mozilla.org
** Against Mozilla.org


== Test Automation Coverage: ==
= Test Automation Coverage: =
* What will the Bedrock unit tests cover?
* What will the Bedrock unit tests cover?
** Where/how frequently will they run?  With each pull request/commit/release?
** Where/how frequently will they run?  With each pull request/commit/release?
Line 103: Line 103:
{{VerifiedUser}}
{{VerifiedUser}}


= References =
== References ==
* [https://wiki.mozilla.org/Firefox/Stub_Attribution Stub Attribution wiki]
* [https://wiki.mozilla.org/Firefox/Stub_Attribution Stub Attribution wiki]
* [https://docs.google.com/document/d/1H59-4zfw0OAFyqfJw71dI0jD7Z-NLvLyowPw6pNhAVs/edit?ts=56e9d8db Stub Attribution Project Plan] (Google Doc)
* [https://docs.google.com/document/d/1H59-4zfw0OAFyqfJw71dI0jD7Z-NLvLyowPw6pNhAVs/edit?ts=56e9d8db Stub Attribution Project Plan] (Google Doc)
* [https://docs.google.com/document/d/1Y8PYGk6IK19N4-2IqoBK3Eiq9BPc6vV0pfGGiqmYOjM/edit#heading=h.72syj6m0u12d Stub Attribution project's checkin notes] (Google Doc)
* [https://docs.google.com/document/d/1Y8PYGk6IK19N4-2IqoBK3Eiq9BPc6vV0pfGGiqmYOjM/edit#heading=h.72syj6m0u12d Stub Attribution project's checkin notes] (Google Doc)

Revision as of 01:41, 8 November 2016

Stub Attribution Test Plan

Dependencies (tools/systems):

Acceptance Criteria

In order to begin testing, the following are needed:

Bugzilla query error

Array ( [type] => error [message] => http-bad-status [params] => Array ( [0] => 429 [1] => Unknown Error ) ) 1

  1. a staged or dark-launched Mozilla.org instance ready with Download-button logic and passed-in attribution_code (from bug 1279291), which:
  2. ...uses the AJAX service to sign Stub-Attribution URLs with a SHA-246 HMAC hash (bug 1278981)
  3. Bouncer (download.mozilla.org) logic updated to ignore attribution_code for XP users
  4. Firefox stub installer binaries which include the stub attribution_code's post-signing data capability available and pointed to...
  5. production-ready stubdownloader.prod.mozaws.net service/instance

Open Issues

Questions:

  1. How (or can we even?) establish a reasonable performance metric around downloading the stub installer, currently?
    1. ...so we can measure against this baseline when we test the dynamic vs. cached-downloads Stub-Attribution Service
  2. All (supported) Windows platforms, or?
  3. Which IE + Windows versions should get the Stub Attribution (SHA-256)
    1. By the looks of bug 1304538, IE 6-8 should get SHA-1
      1. So they're not eligible for this, right?
  4. Which Firefox edition(s)?
    1. Firefox 50 release, or perhaps Beta
  5. How to test (all five?) codes/fields?
    1. Source
    2. Medium
    3. Campaign
    4. Content
    5. "Referrer" alone?
      1. Which specific browsers (vendors + versions) properly support it/if have it enabled, we'll honor the setting?
  6. Which locale(s)?
  7. Entry-points on Mozilla.com. Which page(s)? Or all download pages?
    1. https://www.mozilla.org/en-US/firefox/all/
    2. https://www.mozilla.org/en-US/firefox/new/?scene=2 (and do the ?scene=[] parameters matter?)
    3. Should the attribution code(s) be present on Download buttons when JavaScript is disabled?
  8. How/who checks the Telemetry ping from the client? Via Dashboard?
  9. Do we need to cover the upgrade-path scenario? i.e.:
    1. user downloads and installs using the special stub installer w/tracking code
    2. we verify correct pings, etc.
    3. user upgrades later to a newer version of Firefox (pave-over install)
      1. do we still check for this ping?
  10. How about the successfully installed, then uninstalled case: check to see that client no longer sends ping?
  11. Should we test/what should happen in the double-install case? (Install, then install again w+w/o uninstalling the 1st binary.)
    1. Similarly, what about the a) install stub w/attribution b) upgrade to a later version of Firefox case?

Testing Approaches

Manual Tests:

  1. Positive (happy-path) Tests:
    1. Do Not Track disabled
      • Click an ad banner or link which has an attribution (source? medium? campaign? content? referrer?) code
      • Verify that the URL which takes you to a Mozilla.org download page contains a stub_attcode with a valid param
      • Verify that the same valid stub_attcode param/value gets passed to the Mozilla.org Download Firefox button
      • Download and install the stub installer
      • Verify (how?) that upon successful installation, the stub installer sends a "success!" ping with the same stub_attcode param/value

Regression Testing

  • All browsers available on Windows XP/Vista (test IE 6, IE 7, Chrome) except for Firefox should still get the SHA-1 stub installer

Negative Testing

  1. Ensure other installers/binaries don't have/pass on the URL param/stub code
    1. e.g. Mac, Linux, full Firefox for Windows installers

Performance Testing

Load/Soak Tests

Fuzz/Security Testing

  • Purpose:
    • Surface potential incorrectly-handled errors (tracebacks/HTTP 5xx, etc.) and potential security issues
  • Likely using OWASP ZAP, either manually and/or via the CLI, using Docker/Jenkins
    • Against Bouncer
    • Against Stub Downloader service
    • Against Mozilla.org

Test Automation Coverage:

  • What will the Bedrock unit tests cover?
    • Where/how frequently will they run? With each pull request/commit/release?
  • What will the Bouncer tests cover?
    • Where/how frequently will they run? With each pull request/commit/release? On a cron?


References