Merge branch '17009-s3-bucket-vhost'
[arvados.git] / services / keep-web / s3_test.go
1 // Copyright (C) The Arvados Authors. All rights reserved.
2 //
3 // SPDX-License-Identifier: AGPL-3.0
4
5 package main
6
7 import (
8         "bytes"
9         "crypto/rand"
10         "fmt"
11         "io/ioutil"
12         "net/http"
13         "os"
14         "os/exec"
15         "strings"
16         "sync"
17         "time"
18
19         "git.arvados.org/arvados.git/sdk/go/arvados"
20         "git.arvados.org/arvados.git/sdk/go/arvadosclient"
21         "git.arvados.org/arvados.git/sdk/go/arvadostest"
22         "git.arvados.org/arvados.git/sdk/go/keepclient"
23         "github.com/AdRoll/goamz/aws"
24         "github.com/AdRoll/goamz/s3"
25         check "gopkg.in/check.v1"
26 )
27
28 type s3stage struct {
29         arv        *arvados.Client
30         ac         *arvadosclient.ArvadosClient
31         kc         *keepclient.KeepClient
32         proj       arvados.Group
33         projbucket *s3.Bucket
34         coll       arvados.Collection
35         collbucket *s3.Bucket
36 }
37
38 func (s *IntegrationSuite) s3setup(c *check.C) s3stage {
39         var proj arvados.Group
40         var coll arvados.Collection
41         arv := arvados.NewClientFromEnv()
42         arv.AuthToken = arvadostest.ActiveToken
43         err := arv.RequestAndDecode(&proj, "POST", "arvados/v1/groups", nil, map[string]interface{}{
44                 "group": map[string]interface{}{
45                         "group_class": "project",
46                         "name":        "keep-web s3 test",
47                 },
48                 "ensure_unique_name": true,
49         })
50         c.Assert(err, check.IsNil)
51         err = arv.RequestAndDecode(&coll, "POST", "arvados/v1/collections", nil, map[string]interface{}{"collection": map[string]interface{}{
52                 "owner_uuid":    proj.UUID,
53                 "name":          "keep-web s3 test collection",
54                 "manifest_text": ". d41d8cd98f00b204e9800998ecf8427e+0 0:0:emptyfile\n./emptydir d41d8cd98f00b204e9800998ecf8427e+0 0:0:.\n",
55         }})
56         c.Assert(err, check.IsNil)
57         ac, err := arvadosclient.New(arv)
58         c.Assert(err, check.IsNil)
59         kc, err := keepclient.MakeKeepClient(ac)
60         c.Assert(err, check.IsNil)
61         fs, err := coll.FileSystem(arv, kc)
62         c.Assert(err, check.IsNil)
63         f, err := fs.OpenFile("sailboat.txt", os.O_CREATE|os.O_WRONLY, 0644)
64         c.Assert(err, check.IsNil)
65         _, err = f.Write([]byte("⛵\n"))
66         c.Assert(err, check.IsNil)
67         err = f.Close()
68         c.Assert(err, check.IsNil)
69         err = fs.Sync()
70         c.Assert(err, check.IsNil)
71         err = arv.RequestAndDecode(&coll, "GET", "arvados/v1/collections/"+coll.UUID, nil, nil)
72         c.Assert(err, check.IsNil)
73
74         auth := aws.NewAuth(arvadostest.ActiveTokenUUID, arvadostest.ActiveToken, "", time.Now().Add(time.Hour))
75         region := aws.Region{
76                 Name:       s.testServer.Addr,
77                 S3Endpoint: "http://" + s.testServer.Addr,
78         }
79         client := s3.New(*auth, region)
80         client.Signature = aws.V4Signature
81         return s3stage{
82                 arv:  arv,
83                 ac:   ac,
84                 kc:   kc,
85                 proj: proj,
86                 projbucket: &s3.Bucket{
87                         S3:   client,
88                         Name: proj.UUID,
89                 },
90                 coll: coll,
91                 collbucket: &s3.Bucket{
92                         S3:   client,
93                         Name: coll.UUID,
94                 },
95         }
96 }
97
98 func (stage s3stage) teardown(c *check.C) {
99         if stage.coll.UUID != "" {
100                 err := stage.arv.RequestAndDecode(&stage.coll, "DELETE", "arvados/v1/collections/"+stage.coll.UUID, nil, nil)
101                 c.Check(err, check.IsNil)
102         }
103         if stage.proj.UUID != "" {
104                 err := stage.arv.RequestAndDecode(&stage.proj, "DELETE", "arvados/v1/groups/"+stage.proj.UUID, nil, nil)
105                 c.Check(err, check.IsNil)
106         }
107 }
108
109 func (s *IntegrationSuite) TestS3Signatures(c *check.C) {
110         stage := s.s3setup(c)
111         defer stage.teardown(c)
112
113         bucket := stage.collbucket
114         for _, trial := range []struct {
115                 success   bool
116                 signature int
117                 accesskey string
118                 secretkey string
119         }{
120                 {true, aws.V2Signature, arvadostest.ActiveToken, "none"},
121                 {false, aws.V2Signature, "none", "none"},
122                 {false, aws.V2Signature, "none", arvadostest.ActiveToken},
123
124                 {true, aws.V4Signature, arvadostest.ActiveTokenUUID, arvadostest.ActiveToken},
125                 {true, aws.V4Signature, arvadostest.ActiveToken, arvadostest.ActiveToken},
126                 {false, aws.V4Signature, arvadostest.ActiveToken, ""},
127                 {false, aws.V4Signature, arvadostest.ActiveToken, "none"},
128                 {false, aws.V4Signature, "none", arvadostest.ActiveToken},
129                 {false, aws.V4Signature, "none", "none"},
130         } {
131                 c.Logf("%#v", trial)
132                 bucket.S3.Auth = *(aws.NewAuth(trial.accesskey, trial.secretkey, "", time.Now().Add(time.Hour)))
133                 bucket.S3.Signature = trial.signature
134                 _, err := bucket.GetReader("emptyfile")
135                 if trial.success {
136                         c.Check(err, check.IsNil)
137                 } else {
138                         c.Check(err, check.NotNil)
139                 }
140         }
141 }
142
143 func (s *IntegrationSuite) TestS3HeadBucket(c *check.C) {
144         stage := s.s3setup(c)
145         defer stage.teardown(c)
146
147         for _, bucket := range []*s3.Bucket{stage.collbucket, stage.projbucket} {
148                 c.Logf("bucket %s", bucket.Name)
149                 exists, err := bucket.Exists("")
150                 c.Check(err, check.IsNil)
151                 c.Check(exists, check.Equals, true)
152         }
153 }
154
155 func (s *IntegrationSuite) TestS3CollectionGetObject(c *check.C) {
156         stage := s.s3setup(c)
157         defer stage.teardown(c)
158         s.testS3GetObject(c, stage.collbucket, "")
159 }
160 func (s *IntegrationSuite) TestS3ProjectGetObject(c *check.C) {
161         stage := s.s3setup(c)
162         defer stage.teardown(c)
163         s.testS3GetObject(c, stage.projbucket, stage.coll.Name+"/")
164 }
165 func (s *IntegrationSuite) testS3GetObject(c *check.C, bucket *s3.Bucket, prefix string) {
166         rdr, err := bucket.GetReader(prefix + "emptyfile")
167         c.Assert(err, check.IsNil)
168         buf, err := ioutil.ReadAll(rdr)
169         c.Check(err, check.IsNil)
170         c.Check(len(buf), check.Equals, 0)
171         err = rdr.Close()
172         c.Check(err, check.IsNil)
173
174         // GetObject
175         rdr, err = bucket.GetReader(prefix + "missingfile")
176         c.Check(err, check.ErrorMatches, `404 Not Found`)
177
178         // HeadObject
179         exists, err := bucket.Exists(prefix + "missingfile")
180         c.Check(err, check.IsNil)
181         c.Check(exists, check.Equals, false)
182
183         // GetObject
184         rdr, err = bucket.GetReader(prefix + "sailboat.txt")
185         c.Assert(err, check.IsNil)
186         buf, err = ioutil.ReadAll(rdr)
187         c.Check(err, check.IsNil)
188         c.Check(buf, check.DeepEquals, []byte("⛵\n"))
189         err = rdr.Close()
190         c.Check(err, check.IsNil)
191
192         // HeadObject
193         resp, err := bucket.Head(prefix+"sailboat.txt", nil)
194         c.Check(err, check.IsNil)
195         c.Check(resp.StatusCode, check.Equals, http.StatusOK)
196         c.Check(resp.ContentLength, check.Equals, int64(4))
197 }
198
199 func (s *IntegrationSuite) TestS3CollectionPutObjectSuccess(c *check.C) {
200         stage := s.s3setup(c)
201         defer stage.teardown(c)
202         s.testS3PutObjectSuccess(c, stage.collbucket, "")
203 }
204 func (s *IntegrationSuite) TestS3ProjectPutObjectSuccess(c *check.C) {
205         stage := s.s3setup(c)
206         defer stage.teardown(c)
207         s.testS3PutObjectSuccess(c, stage.projbucket, stage.coll.Name+"/")
208 }
209 func (s *IntegrationSuite) testS3PutObjectSuccess(c *check.C, bucket *s3.Bucket, prefix string) {
210         for _, trial := range []struct {
211                 path        string
212                 size        int
213                 contentType string
214         }{
215                 {
216                         path:        "newfile",
217                         size:        128000000,
218                         contentType: "application/octet-stream",
219                 }, {
220                         path:        "newdir/newfile",
221                         size:        1 << 26,
222                         contentType: "application/octet-stream",
223                 }, {
224                         path:        "newdir1/newdir2/newfile",
225                         size:        0,
226                         contentType: "application/octet-stream",
227                 }, {
228                         path:        "newdir1/newdir2/newdir3/",
229                         size:        0,
230                         contentType: "application/x-directory",
231                 },
232         } {
233                 c.Logf("=== %v", trial)
234
235                 objname := prefix + trial.path
236
237                 _, err := bucket.GetReader(objname)
238                 c.Assert(err, check.ErrorMatches, `404 Not Found`)
239
240                 buf := make([]byte, trial.size)
241                 rand.Read(buf)
242
243                 err = bucket.PutReader(objname, bytes.NewReader(buf), int64(len(buf)), trial.contentType, s3.Private, s3.Options{})
244                 c.Check(err, check.IsNil)
245
246                 rdr, err := bucket.GetReader(objname)
247                 if strings.HasSuffix(trial.path, "/") && !s.testServer.Config.cluster.Collections.S3FolderObjects {
248                         c.Check(err, check.NotNil)
249                         continue
250                 } else if !c.Check(err, check.IsNil) {
251                         continue
252                 }
253                 buf2, err := ioutil.ReadAll(rdr)
254                 c.Check(err, check.IsNil)
255                 c.Check(buf2, check.HasLen, len(buf))
256                 c.Check(bytes.Equal(buf, buf2), check.Equals, true)
257         }
258 }
259
260 func (s *IntegrationSuite) TestS3ProjectPutObjectNotSupported(c *check.C) {
261         stage := s.s3setup(c)
262         defer stage.teardown(c)
263         bucket := stage.projbucket
264
265         for _, trial := range []struct {
266                 path        string
267                 size        int
268                 contentType string
269         }{
270                 {
271                         path:        "newfile",
272                         size:        1234,
273                         contentType: "application/octet-stream",
274                 }, {
275                         path:        "newdir/newfile",
276                         size:        1234,
277                         contentType: "application/octet-stream",
278                 }, {
279                         path:        "newdir2/",
280                         size:        0,
281                         contentType: "application/x-directory",
282                 },
283         } {
284                 c.Logf("=== %v", trial)
285
286                 _, err := bucket.GetReader(trial.path)
287                 c.Assert(err, check.ErrorMatches, `404 Not Found`)
288
289                 buf := make([]byte, trial.size)
290                 rand.Read(buf)
291
292                 err = bucket.PutReader(trial.path, bytes.NewReader(buf), int64(len(buf)), trial.contentType, s3.Private, s3.Options{})
293                 c.Check(err, check.ErrorMatches, `400 Bad Request`)
294
295                 _, err = bucket.GetReader(trial.path)
296                 c.Assert(err, check.ErrorMatches, `404 Not Found`)
297         }
298 }
299
300 func (s *IntegrationSuite) TestS3CollectionDeleteObject(c *check.C) {
301         stage := s.s3setup(c)
302         defer stage.teardown(c)
303         s.testS3DeleteObject(c, stage.collbucket, "")
304 }
305 func (s *IntegrationSuite) TestS3ProjectDeleteObject(c *check.C) {
306         stage := s.s3setup(c)
307         defer stage.teardown(c)
308         s.testS3DeleteObject(c, stage.projbucket, stage.coll.Name+"/")
309 }
310 func (s *IntegrationSuite) testS3DeleteObject(c *check.C, bucket *s3.Bucket, prefix string) {
311         s.testServer.Config.cluster.Collections.S3FolderObjects = true
312         for _, trial := range []struct {
313                 path string
314         }{
315                 {"/"},
316                 {"nonexistentfile"},
317                 {"emptyfile"},
318                 {"sailboat.txt"},
319                 {"sailboat.txt/"},
320                 {"emptydir"},
321                 {"emptydir/"},
322         } {
323                 objname := prefix + trial.path
324                 comment := check.Commentf("objname %q", objname)
325
326                 err := bucket.Del(objname)
327                 if trial.path == "/" {
328                         c.Check(err, check.NotNil)
329                         continue
330                 }
331                 c.Check(err, check.IsNil, comment)
332                 _, err = bucket.GetReader(objname)
333                 c.Check(err, check.NotNil, comment)
334         }
335 }
336
337 func (s *IntegrationSuite) TestS3CollectionPutObjectFailure(c *check.C) {
338         stage := s.s3setup(c)
339         defer stage.teardown(c)
340         s.testS3PutObjectFailure(c, stage.collbucket, "")
341 }
342 func (s *IntegrationSuite) TestS3ProjectPutObjectFailure(c *check.C) {
343         stage := s.s3setup(c)
344         defer stage.teardown(c)
345         s.testS3PutObjectFailure(c, stage.projbucket, stage.coll.Name+"/")
346 }
347 func (s *IntegrationSuite) testS3PutObjectFailure(c *check.C, bucket *s3.Bucket, prefix string) {
348         s.testServer.Config.cluster.Collections.S3FolderObjects = false
349
350         // Can't use V4 signature for these tests, because
351         // double-slash is incorrectly cleaned by the aws.V4Signature,
352         // resulting in a "bad signature" error. (Cleaning the path is
353         // appropriate for other services, but not in S3 where object
354         // names "foo//bar" and "foo/bar" are semantically different.)
355         bucket.S3.Auth = *(aws.NewAuth(arvadostest.ActiveToken, "none", "", time.Now().Add(time.Hour)))
356         bucket.S3.Signature = aws.V2Signature
357
358         var wg sync.WaitGroup
359         for _, trial := range []struct {
360                 path string
361         }{
362                 {
363                         path: "emptyfile/newname", // emptyfile exists, see s3setup()
364                 }, {
365                         path: "emptyfile/", // emptyfile exists, see s3setup()
366                 }, {
367                         path: "emptydir", // dir already exists, see s3setup()
368                 }, {
369                         path: "emptydir/",
370                 }, {
371                         path: "emptydir//",
372                 }, {
373                         path: "newdir/",
374                 }, {
375                         path: "newdir//",
376                 }, {
377                         path: "/",
378                 }, {
379                         path: "//",
380                 }, {
381                         path: "foo//bar",
382                 }, {
383                         path: "",
384                 },
385         } {
386                 trial := trial
387                 wg.Add(1)
388                 go func() {
389                         defer wg.Done()
390                         c.Logf("=== %v", trial)
391
392                         objname := prefix + trial.path
393
394                         buf := make([]byte, 1234)
395                         rand.Read(buf)
396
397                         err := bucket.PutReader(objname, bytes.NewReader(buf), int64(len(buf)), "application/octet-stream", s3.Private, s3.Options{})
398                         if !c.Check(err, check.ErrorMatches, `400 Bad.*`, check.Commentf("PUT %q should fail", objname)) {
399                                 return
400                         }
401
402                         if objname != "" && objname != "/" {
403                                 _, err = bucket.GetReader(objname)
404                                 c.Check(err, check.ErrorMatches, `404 Not Found`, check.Commentf("GET %q should return 404", objname))
405                         }
406                 }()
407         }
408         wg.Wait()
409 }
410
411 func (stage *s3stage) writeBigDirs(c *check.C, dirs int, filesPerDir int) {
412         fs, err := stage.coll.FileSystem(stage.arv, stage.kc)
413         c.Assert(err, check.IsNil)
414         for d := 0; d < dirs; d++ {
415                 dir := fmt.Sprintf("dir%d", d)
416                 c.Assert(fs.Mkdir(dir, 0755), check.IsNil)
417                 for i := 0; i < filesPerDir; i++ {
418                         f, err := fs.OpenFile(fmt.Sprintf("%s/file%d.txt", dir, i), os.O_CREATE|os.O_WRONLY, 0644)
419                         c.Assert(err, check.IsNil)
420                         c.Assert(f.Close(), check.IsNil)
421                 }
422         }
423         c.Assert(fs.Sync(), check.IsNil)
424 }
425
426 func (s *IntegrationSuite) TestS3GetBucketVersioning(c *check.C) {
427         stage := s.s3setup(c)
428         defer stage.teardown(c)
429         for _, bucket := range []*s3.Bucket{stage.collbucket, stage.projbucket} {
430                 req, err := http.NewRequest("GET", bucket.URL("/"), nil)
431                 c.Check(err, check.IsNil)
432                 req.Header.Set("Authorization", "AWS "+arvadostest.ActiveTokenV2+":none")
433                 req.URL.RawQuery = "versioning"
434                 resp, err := http.DefaultClient.Do(req)
435                 c.Assert(err, check.IsNil)
436                 c.Check(resp.Header.Get("Content-Type"), check.Equals, "application/xml")
437                 buf, err := ioutil.ReadAll(resp.Body)
438                 c.Assert(err, check.IsNil)
439                 c.Check(string(buf), check.Equals, "<?xml version=\"1.0\" encoding=\"UTF-8\"?>\n<VersioningConfiguration xmlns=\"http://s3.amazonaws.com/doc/2006-03-01/\"/>\n")
440         }
441 }
442
443 // If there are no CommonPrefixes entries, the CommonPrefixes XML tag
444 // should not appear at all.
445 func (s *IntegrationSuite) TestS3ListNoCommonPrefixes(c *check.C) {
446         stage := s.s3setup(c)
447         defer stage.teardown(c)
448
449         req, err := http.NewRequest("GET", stage.collbucket.URL("/"), nil)
450         c.Assert(err, check.IsNil)
451         req.Header.Set("Authorization", "AWS "+arvadostest.ActiveTokenV2+":none")
452         req.URL.RawQuery = "prefix=asdfasdfasdf&delimiter=/"
453         resp, err := http.DefaultClient.Do(req)
454         c.Assert(err, check.IsNil)
455         buf, err := ioutil.ReadAll(resp.Body)
456         c.Assert(err, check.IsNil)
457         c.Check(string(buf), check.Not(check.Matches), `(?ms).*CommonPrefixes.*`)
458 }
459
460 // If there is no delimiter in the request, or the results are not
461 // truncated, the NextMarker XML tag should not appear in the response
462 // body.
463 func (s *IntegrationSuite) TestS3ListNoNextMarker(c *check.C) {
464         stage := s.s3setup(c)
465         defer stage.teardown(c)
466
467         for _, query := range []string{"prefix=e&delimiter=/", ""} {
468                 req, err := http.NewRequest("GET", stage.collbucket.URL("/"), nil)
469                 c.Assert(err, check.IsNil)
470                 req.Header.Set("Authorization", "AWS "+arvadostest.ActiveTokenV2+":none")
471                 req.URL.RawQuery = query
472                 resp, err := http.DefaultClient.Do(req)
473                 c.Assert(err, check.IsNil)
474                 buf, err := ioutil.ReadAll(resp.Body)
475                 c.Assert(err, check.IsNil)
476                 c.Check(string(buf), check.Not(check.Matches), `(?ms).*NextMarker.*`)
477         }
478 }
479
480 // List response should include KeyCount field.
481 func (s *IntegrationSuite) TestS3ListKeyCount(c *check.C) {
482         stage := s.s3setup(c)
483         defer stage.teardown(c)
484
485         req, err := http.NewRequest("GET", stage.collbucket.URL("/"), nil)
486         c.Assert(err, check.IsNil)
487         req.Header.Set("Authorization", "AWS "+arvadostest.ActiveTokenV2+":none")
488         req.URL.RawQuery = "prefix=&delimiter=/"
489         resp, err := http.DefaultClient.Do(req)
490         c.Assert(err, check.IsNil)
491         buf, err := ioutil.ReadAll(resp.Body)
492         c.Assert(err, check.IsNil)
493         c.Check(string(buf), check.Matches, `(?ms).*<KeyCount>2</KeyCount>.*`)
494 }
495
496 func (s *IntegrationSuite) TestS3CollectionList(c *check.C) {
497         stage := s.s3setup(c)
498         defer stage.teardown(c)
499
500         var markers int
501         for markers, s.testServer.Config.cluster.Collections.S3FolderObjects = range []bool{false, true} {
502                 dirs := 2
503                 filesPerDir := 1001
504                 stage.writeBigDirs(c, dirs, filesPerDir)
505                 // Total # objects is:
506                 //                 2 file entries from s3setup (emptyfile and sailboat.txt)
507                 //                +1 fake "directory" marker from s3setup (emptydir) (if enabled)
508                 //             +dirs fake "directory" marker from writeBigDirs (dir0/, dir1/) (if enabled)
509                 // +filesPerDir*dirs file entries from writeBigDirs (dir0/file0.txt, etc.)
510                 s.testS3List(c, stage.collbucket, "", 4000, markers+2+(filesPerDir+markers)*dirs)
511                 s.testS3List(c, stage.collbucket, "", 131, markers+2+(filesPerDir+markers)*dirs)
512                 s.testS3List(c, stage.collbucket, "dir0/", 71, filesPerDir+markers)
513         }
514 }
515 func (s *IntegrationSuite) testS3List(c *check.C, bucket *s3.Bucket, prefix string, pageSize, expectFiles int) {
516         c.Logf("testS3List: prefix=%q pageSize=%d S3FolderObjects=%v", prefix, pageSize, s.testServer.Config.cluster.Collections.S3FolderObjects)
517         expectPageSize := pageSize
518         if expectPageSize > 1000 {
519                 expectPageSize = 1000
520         }
521         gotKeys := map[string]s3.Key{}
522         nextMarker := ""
523         pages := 0
524         for {
525                 resp, err := bucket.List(prefix, "", nextMarker, pageSize)
526                 if !c.Check(err, check.IsNil) {
527                         break
528                 }
529                 c.Check(len(resp.Contents) <= expectPageSize, check.Equals, true)
530                 if pages++; !c.Check(pages <= (expectFiles/expectPageSize)+1, check.Equals, true) {
531                         break
532                 }
533                 for _, key := range resp.Contents {
534                         gotKeys[key.Key] = key
535                         if strings.Contains(key.Key, "sailboat.txt") {
536                                 c.Check(key.Size, check.Equals, int64(4))
537                         }
538                 }
539                 if !resp.IsTruncated {
540                         c.Check(resp.NextMarker, check.Equals, "")
541                         break
542                 }
543                 if !c.Check(resp.NextMarker, check.Not(check.Equals), "") {
544                         break
545                 }
546                 nextMarker = resp.NextMarker
547         }
548         c.Check(len(gotKeys), check.Equals, expectFiles)
549 }
550
551 func (s *IntegrationSuite) TestS3CollectionListRollup(c *check.C) {
552         for _, s.testServer.Config.cluster.Collections.S3FolderObjects = range []bool{false, true} {
553                 s.testS3CollectionListRollup(c)
554         }
555 }
556
557 func (s *IntegrationSuite) testS3CollectionListRollup(c *check.C) {
558         stage := s.s3setup(c)
559         defer stage.teardown(c)
560
561         dirs := 2
562         filesPerDir := 500
563         stage.writeBigDirs(c, dirs, filesPerDir)
564         err := stage.collbucket.PutReader("dingbats", &bytes.Buffer{}, 0, "application/octet-stream", s3.Private, s3.Options{})
565         c.Assert(err, check.IsNil)
566         var allfiles []string
567         for marker := ""; ; {
568                 resp, err := stage.collbucket.List("", "", marker, 20000)
569                 c.Check(err, check.IsNil)
570                 for _, key := range resp.Contents {
571                         if len(allfiles) == 0 || allfiles[len(allfiles)-1] != key.Key {
572                                 allfiles = append(allfiles, key.Key)
573                         }
574                 }
575                 marker = resp.NextMarker
576                 if marker == "" {
577                         break
578                 }
579         }
580         markers := 0
581         if s.testServer.Config.cluster.Collections.S3FolderObjects {
582                 markers = 1
583         }
584         c.Check(allfiles, check.HasLen, dirs*(filesPerDir+markers)+3+markers)
585
586         gotDirMarker := map[string]bool{}
587         for _, name := range allfiles {
588                 isDirMarker := strings.HasSuffix(name, "/")
589                 if markers == 0 {
590                         c.Check(isDirMarker, check.Equals, false, check.Commentf("name %q", name))
591                 } else if isDirMarker {
592                         gotDirMarker[name] = true
593                 } else if i := strings.LastIndex(name, "/"); i >= 0 {
594                         c.Check(gotDirMarker[name[:i+1]], check.Equals, true, check.Commentf("name %q", name))
595                         gotDirMarker[name[:i+1]] = true // skip redundant complaints about this dir marker
596                 }
597         }
598
599         for _, trial := range []struct {
600                 prefix    string
601                 delimiter string
602                 marker    string
603         }{
604                 {"", "", ""},
605                 {"di", "/", ""},
606                 {"di", "r", ""},
607                 {"di", "n", ""},
608                 {"dir0", "/", ""},
609                 {"dir0/", "/", ""},
610                 {"dir0/f", "/", ""},
611                 {"dir0", "", ""},
612                 {"dir0/", "", ""},
613                 {"dir0/f", "", ""},
614                 {"dir0", "/", "dir0/file14.txt"},       // no commonprefixes
615                 {"", "", "dir0/file14.txt"},            // middle page, skip walking dir1
616                 {"", "", "dir1/file14.txt"},            // middle page, skip walking dir0
617                 {"", "", "dir1/file498.txt"},           // last page of results
618                 {"dir1/file", "", "dir1/file498.txt"},  // last page of results, with prefix
619                 {"dir1/file", "/", "dir1/file498.txt"}, // last page of results, with prefix + delimiter
620                 {"dir1", "Z", "dir1/file498.txt"},      // delimiter "Z" never appears
621                 {"dir2", "/", ""},                      // prefix "dir2" does not exist
622                 {"", "/", ""},
623         } {
624                 c.Logf("\n\n=== trial %+v markers=%d", trial, markers)
625
626                 maxKeys := 20
627                 resp, err := stage.collbucket.List(trial.prefix, trial.delimiter, trial.marker, maxKeys)
628                 c.Check(err, check.IsNil)
629                 if resp.IsTruncated && trial.delimiter == "" {
630                         // goamz List method fills in the missing
631                         // NextMarker field if resp.IsTruncated, so
632                         // now we can't really tell whether it was
633                         // sent by the server or by goamz. In cases
634                         // where it should be empty but isn't, assume
635                         // it's goamz's fault.
636                         resp.NextMarker = ""
637                 }
638
639                 var expectKeys []string
640                 var expectPrefixes []string
641                 var expectNextMarker string
642                 var expectTruncated bool
643                 for _, key := range allfiles {
644                         full := len(expectKeys)+len(expectPrefixes) >= maxKeys
645                         if !strings.HasPrefix(key, trial.prefix) || key < trial.marker {
646                                 continue
647                         } else if idx := strings.Index(key[len(trial.prefix):], trial.delimiter); trial.delimiter != "" && idx >= 0 {
648                                 prefix := key[:len(trial.prefix)+idx+1]
649                                 if len(expectPrefixes) > 0 && expectPrefixes[len(expectPrefixes)-1] == prefix {
650                                         // same prefix as previous key
651                                 } else if full {
652                                         expectNextMarker = key
653                                         expectTruncated = true
654                                 } else {
655                                         expectPrefixes = append(expectPrefixes, prefix)
656                                 }
657                         } else if full {
658                                 if trial.delimiter != "" {
659                                         expectNextMarker = key
660                                 }
661                                 expectTruncated = true
662                                 break
663                         } else {
664                                 expectKeys = append(expectKeys, key)
665                         }
666                 }
667
668                 var gotKeys []string
669                 for _, key := range resp.Contents {
670                         gotKeys = append(gotKeys, key.Key)
671                 }
672                 var gotPrefixes []string
673                 for _, prefix := range resp.CommonPrefixes {
674                         gotPrefixes = append(gotPrefixes, prefix)
675                 }
676                 commentf := check.Commentf("trial %+v markers=%d", trial, markers)
677                 c.Check(gotKeys, check.DeepEquals, expectKeys, commentf)
678                 c.Check(gotPrefixes, check.DeepEquals, expectPrefixes, commentf)
679                 c.Check(resp.NextMarker, check.Equals, expectNextMarker, commentf)
680                 c.Check(resp.IsTruncated, check.Equals, expectTruncated, commentf)
681                 c.Logf("=== trial %+v keys %q prefixes %q nextMarker %q", trial, gotKeys, gotPrefixes, resp.NextMarker)
682         }
683 }
684
685 // TestS3cmd checks compatibility with the s3cmd command line tool, if
686 // it's installed. As of Debian buster, s3cmd is only in backports, so
687 // `arvados-server install` don't install it, and this test skips if
688 // it's not installed.
689 func (s *IntegrationSuite) TestS3cmd(c *check.C) {
690         if _, err := exec.LookPath("s3cmd"); err != nil {
691                 c.Skip("s3cmd not found")
692                 return
693         }
694
695         stage := s.s3setup(c)
696         defer stage.teardown(c)
697
698         cmd := exec.Command("s3cmd", "--no-ssl", "--host="+s.testServer.Addr, "--host-bucket="+s.testServer.Addr, "--access_key="+arvadostest.ActiveTokenUUID, "--secret_key="+arvadostest.ActiveToken, "ls", "s3://"+arvadostest.FooCollection)
699         buf, err := cmd.CombinedOutput()
700         c.Check(err, check.IsNil)
701         c.Check(string(buf), check.Matches, `.* 3 +s3://`+arvadostest.FooCollection+`/foo\n`)
702 }
703
704 func (s *IntegrationSuite) TestS3BucketInHost(c *check.C) {
705         stage := s.s3setup(c)
706         defer stage.teardown(c)
707
708         hdr, body, _ := s.runCurl(c, "AWS "+arvadostest.ActiveTokenV2+":none", stage.coll.UUID+".collections.example.com", "/sailboat.txt")
709         c.Check(hdr, check.Matches, `(?s)HTTP/1.1 200 OK\r\n.*`)
710         c.Check(body, check.Equals, "⛵\n")
711 }