2016-09-22 12:43:57 +00:00
---
title: About the command Resource
---
# command
Use the `command` InSpec audit resource to test an arbitrary command that is run on the system.
2016-09-27 19:03:23 +00:00
## Syntax
2016-09-22 12:43:57 +00:00
A `command` resource block declares a command to be run, one (or more) expected outputs, and the location to which that output is sent:
describe command('command') do
it { should exist }
its('matcher') { should eq 'output' }
end
where
* `'command'` must specify a command to be run
* `'matcher'` is one of `exit_status`, `stderr`, or `stdout`
* `'output'` tests the output of the command run on the system versus the output value stated in the test
2016-09-27 19:03:23 +00:00
## Matchers
2016-09-22 12:43:57 +00:00
This InSpec audit resource has the following matchers:
2016-09-27 19:03:23 +00:00
### be
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_be" %>
2016-09-27 19:03:23 +00:00
### cmp
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_cmp" %>
2016-09-27 19:03:23 +00:00
### eq
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_eq" %>
2016-09-27 19:03:23 +00:00
### exist
2016-09-22 12:43:57 +00:00
The `exist` matcher tests if a command may be run on the system:
it { should exist }
2016-09-27 19:03:23 +00:00
### exit_status
2016-09-22 12:43:57 +00:00
The `exit_status` matcher tests the exit status for the command:
its('exit_status') { should eq 123 }
2016-09-27 19:03:23 +00:00
### include
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_include" %>
2016-09-27 19:03:23 +00:00
### match
2016-09-22 12:43:57 +00:00
<%= partial "/shared/matcher_match" %>
2016-09-27 19:03:23 +00:00
### stderr
2016-09-22 12:43:57 +00:00
The `stderr` matcher tests results of the command as returned in standard error (stderr):
its('stderr') { should eq 'error' }
2016-09-27 19:03:23 +00:00
### stdout
2016-09-22 12:43:57 +00:00
The `stdout` matcher tests results of the command as returned in standard output (stdout). The following example shows matching output using a regular expression:
describe command('echo 1') do
its('stdout') { should match (/[0-9]/) }
end
2016-09-27 19:03:23 +00:00
## Examples
2016-09-22 12:43:57 +00:00
The following examples show how to use this InSpec audit resource.
2016-09-27 19:03:23 +00:00
### Test for PostgreSQL database running a RC, development, or beta release
2016-09-22 12:43:57 +00:00
describe command('psql -V') do
its('stdout') { should eq '/RC/' }
its('stdout') { should_not eq '/DEVEL/' }
its('stdout') { should_not eq '/BETA/' }
end
2016-09-27 19:03:23 +00:00
### Test standard output (stdout)
2016-09-22 12:43:57 +00:00
describe command('echo hello') do
2017-01-16 03:30:57 +00:00
its('stdout') { should eq "hello\n" }
2016-09-22 12:43:57 +00:00
its('stderr') { should eq '' }
its('exit_status') { should eq 0 }
end
2016-09-27 19:03:23 +00:00
### Test standard error (stderr)
2016-09-22 12:43:57 +00:00
describe command('>&2 echo error') do
its('stdout') { should eq '' }
2017-01-16 03:30:57 +00:00
its('stderr') { should eq "error\n" }
2016-09-22 12:43:57 +00:00
its('exit_status') { should eq 0 }
end
2016-09-27 19:03:23 +00:00
### Test an exit status code
2016-09-22 12:43:57 +00:00
describe command('exit 123') do
its('stdout') { should eq '' }
its('stderr') { should eq '' }
its('exit_status') { should eq 123 }
end
2016-09-27 19:03:23 +00:00
### Test if the command shell exists
2016-09-22 12:43:57 +00:00
describe command('/bin/sh').exist? do
it { should eq true }
end
2016-09-27 19:03:23 +00:00
### Test for a command that should not exist
2016-09-22 12:43:57 +00:00
describe command('this is not existing').exist? do
it { should eq false }
end
2016-09-27 19:03:23 +00:00
### Verify NTP
2016-09-22 12:43:57 +00:00
The following example shows how to use the `file` audit resource to verify if the `ntp.conf` and `leap-seconds` files are present, and then the `command` resource to verify if NTP is installed and running:
describe file('/etc/ntp.conf') do
it { should be_file }
end
describe file('/etc/ntp.leapseconds') do
it { should be_file }
end
describe command('pgrep ntp') do
its('exit_status') { should eq 0 }
end
2016-09-27 19:03:23 +00:00
### Verify WiX
2016-09-22 12:43:57 +00:00
Wix includes serveral tools -- such as `candle` (preprocesses and compiles source files into object files), `light` (links and binds object files to an installer database), and `heat` (harvests files from various input formats). The following example uses a whitespace array and the `file` audit resource to verify if these three tools are present:
%w(
candle.exe
heat.exe
light.exe
).each do |utility|
2016-09-27 19:03:23 +00:00
describe file("C:/wix/##{utility}") do
2016-09-22 12:43:57 +00:00
it { should be_file }
end
end