Add 'apps/arv-web/' from commit 'f9732ad8460d013c2f28363655d0d1b91894dca5'
[arvados.git] / sdk / python / tests / test_keep_client.py
1 import hashlib
2 import mock
3 import os
4 import re
5 import socket
6 import unittest
7 import urlparse
8
9 import arvados
10 import arvados.retry
11 import arvados_testutil as tutil
12 import run_test_server
13
14 class KeepTestCase(run_test_server.TestCaseWithServers):
15     MAIN_SERVER = {}
16     KEEP_SERVER = {}
17
18     @classmethod
19     def setUpClass(cls):
20         super(KeepTestCase, cls).setUpClass()
21         run_test_server.authorize_with("admin")
22         cls.api_client = arvados.api('v1')
23         cls.keep_client = arvados.KeepClient(api_client=cls.api_client,
24                                              proxy='', local_store='')
25
26     def test_KeepBasicRWTest(self):
27         foo_locator = self.keep_client.put('foo')
28         self.assertRegexpMatches(
29             foo_locator,
30             '^acbd18db4cc2f85cedef654fccc4a4d8\+3',
31             'wrong md5 hash from Keep.put("foo"): ' + foo_locator)
32         self.assertEqual(self.keep_client.get(foo_locator),
33                          'foo',
34                          'wrong content from Keep.get(md5("foo"))')
35
36     def test_KeepBinaryRWTest(self):
37         blob_str = '\xff\xfe\xf7\x00\x01\x02'
38         blob_locator = self.keep_client.put(blob_str)
39         self.assertRegexpMatches(
40             blob_locator,
41             '^7fc7c53b45e53926ba52821140fef396\+6',
42             ('wrong locator from Keep.put(<binarydata>):' + blob_locator))
43         self.assertEqual(self.keep_client.get(blob_locator),
44                          blob_str,
45                          'wrong content from Keep.get(md5(<binarydata>))')
46
47     def test_KeepLongBinaryRWTest(self):
48         blob_str = '\xff\xfe\xfd\xfc\x00\x01\x02\x03'
49         for i in range(0,23):
50             blob_str = blob_str + blob_str
51         blob_locator = self.keep_client.put(blob_str)
52         self.assertRegexpMatches(
53             blob_locator,
54             '^84d90fc0d8175dd5dcfab04b999bc956\+67108864',
55             ('wrong locator from Keep.put(<binarydata>): ' + blob_locator))
56         self.assertEqual(self.keep_client.get(blob_locator),
57                          blob_str,
58                          'wrong content from Keep.get(md5(<binarydata>))')
59
60     def test_KeepSingleCopyRWTest(self):
61         blob_str = '\xff\xfe\xfd\xfc\x00\x01\x02\x03'
62         blob_locator = self.keep_client.put(blob_str, copies=1)
63         self.assertRegexpMatches(
64             blob_locator,
65             '^c902006bc98a3eb4a3663b65ab4a6fab\+8',
66             ('wrong locator from Keep.put(<binarydata>): ' + blob_locator))
67         self.assertEqual(self.keep_client.get(blob_locator),
68                          blob_str,
69                          'wrong content from Keep.get(md5(<binarydata>))')
70
71     def test_KeepEmptyCollectionTest(self):
72         blob_locator = self.keep_client.put('', copies=1)
73         self.assertRegexpMatches(
74             blob_locator,
75             '^d41d8cd98f00b204e9800998ecf8427e\+0',
76             ('wrong locator from Keep.put(""): ' + blob_locator))
77
78
79 class KeepPermissionTestCase(run_test_server.TestCaseWithServers):
80     MAIN_SERVER = {}
81     KEEP_SERVER = {'blob_signing_key': 'abcdefghijk0123456789',
82                    'enforce_permissions': True}
83
84     def test_KeepBasicRWTest(self):
85         run_test_server.authorize_with('active')
86         keep_client = arvados.KeepClient()
87         foo_locator = keep_client.put('foo')
88         self.assertRegexpMatches(
89             foo_locator,
90             r'^acbd18db4cc2f85cedef654fccc4a4d8\+3\+A[a-f0-9]+@[a-f0-9]+$',
91             'invalid locator from Keep.put("foo"): ' + foo_locator)
92         self.assertEqual(keep_client.get(foo_locator),
93                          'foo',
94                          'wrong content from Keep.get(md5("foo"))')
95
96         # GET with an unsigned locator => NotFound
97         bar_locator = keep_client.put('bar')
98         unsigned_bar_locator = "37b51d194a7513e45b56f6524f2d51f2+3"
99         self.assertRegexpMatches(
100             bar_locator,
101             r'^37b51d194a7513e45b56f6524f2d51f2\+3\+A[a-f0-9]+@[a-f0-9]+$',
102             'invalid locator from Keep.put("bar"): ' + bar_locator)
103         self.assertRaises(arvados.errors.NotFoundError,
104                           keep_client.get,
105                           unsigned_bar_locator)
106
107         # GET from a different user => NotFound
108         run_test_server.authorize_with('spectator')
109         self.assertRaises(arvados.errors.NotFoundError,
110                           arvados.Keep.get,
111                           bar_locator)
112
113         # Unauthenticated GET for a signed locator => NotFound
114         # Unauthenticated GET for an unsigned locator => NotFound
115         keep_client.api_token = ''
116         self.assertRaises(arvados.errors.NotFoundError,
117                           keep_client.get,
118                           bar_locator)
119         self.assertRaises(arvados.errors.NotFoundError,
120                           keep_client.get,
121                           unsigned_bar_locator)
122
123
124 # KeepOptionalPermission: starts Keep with --permission-key-file
125 # but not --enforce-permissions (i.e. generate signatures on PUT
126 # requests, but do not require them for GET requests)
127 #
128 # All of these requests should succeed when permissions are optional:
129 # * authenticated request, signed locator
130 # * authenticated request, unsigned locator
131 # * unauthenticated request, signed locator
132 # * unauthenticated request, unsigned locator
133 class KeepOptionalPermission(run_test_server.TestCaseWithServers):
134     MAIN_SERVER = {}
135     KEEP_SERVER = {'blob_signing_key': 'abcdefghijk0123456789',
136                    'enforce_permissions': False}
137
138     @classmethod
139     def setUpClass(cls):
140         super(KeepOptionalPermission, cls).setUpClass()
141         run_test_server.authorize_with("admin")
142         cls.api_client = arvados.api('v1')
143
144     def setUp(self):
145         super(KeepOptionalPermission, self).setUp()
146         self.keep_client = arvados.KeepClient(api_client=self.api_client,
147                                               proxy='', local_store='')
148
149     def _put_foo_and_check(self):
150         signed_locator = self.keep_client.put('foo')
151         self.assertRegexpMatches(
152             signed_locator,
153             r'^acbd18db4cc2f85cedef654fccc4a4d8\+3\+A[a-f0-9]+@[a-f0-9]+$',
154             'invalid locator from Keep.put("foo"): ' + signed_locator)
155         return signed_locator
156
157     def test_KeepAuthenticatedSignedTest(self):
158         signed_locator = self._put_foo_and_check()
159         self.assertEqual(self.keep_client.get(signed_locator),
160                          'foo',
161                          'wrong content from Keep.get(md5("foo"))')
162
163     def test_KeepAuthenticatedUnsignedTest(self):
164         signed_locator = self._put_foo_and_check()
165         self.assertEqual(self.keep_client.get("acbd18db4cc2f85cedef654fccc4a4d8"),
166                          'foo',
167                          'wrong content from Keep.get(md5("foo"))')
168
169     def test_KeepUnauthenticatedSignedTest(self):
170         # Check that signed GET requests work even when permissions
171         # enforcement is off.
172         signed_locator = self._put_foo_and_check()
173         self.keep_client.api_token = ''
174         self.assertEqual(self.keep_client.get(signed_locator),
175                          'foo',
176                          'wrong content from Keep.get(md5("foo"))')
177
178     def test_KeepUnauthenticatedUnsignedTest(self):
179         # Since --enforce-permissions is not in effect, GET requests
180         # need not be authenticated.
181         signed_locator = self._put_foo_and_check()
182         self.keep_client.api_token = ''
183         self.assertEqual(self.keep_client.get("acbd18db4cc2f85cedef654fccc4a4d8"),
184                          'foo',
185                          'wrong content from Keep.get(md5("foo"))')
186
187
188 class KeepProxyTestCase(run_test_server.TestCaseWithServers):
189     MAIN_SERVER = {}
190     KEEP_SERVER = {}
191     KEEP_PROXY_SERVER = {'auth': 'admin'}
192
193     @classmethod
194     def setUpClass(cls):
195         super(KeepProxyTestCase, cls).setUpClass()
196         cls.api_client = arvados.api('v1')
197
198     def tearDown(self):
199         arvados.config.settings().pop('ARVADOS_EXTERNAL_CLIENT', None)
200         super(KeepProxyTestCase, self).tearDown()
201
202     def test_KeepProxyTest1(self):
203         # Will use ARVADOS_KEEP_PROXY environment variable that is set by
204         # setUpClass().
205         keep_client = arvados.KeepClient(api_client=self.api_client,
206                                          local_store='')
207         baz_locator = keep_client.put('baz')
208         self.assertRegexpMatches(
209             baz_locator,
210             '^73feffa4b7f6bb68e44cf984c85f6e88\+3',
211             'wrong md5 hash from Keep.put("baz"): ' + baz_locator)
212         self.assertEqual(keep_client.get(baz_locator),
213                          'baz',
214                          'wrong content from Keep.get(md5("baz"))')
215         self.assertTrue(keep_client.using_proxy)
216
217     def test_KeepProxyTest2(self):
218         # Don't instantiate the proxy directly, but set the X-External-Client
219         # header.  The API server should direct us to the proxy.
220         arvados.config.settings()['ARVADOS_EXTERNAL_CLIENT'] = 'true'
221         keep_client = arvados.KeepClient(api_client=self.api_client,
222                                          proxy='', local_store='')
223         baz_locator = keep_client.put('baz2')
224         self.assertRegexpMatches(
225             baz_locator,
226             '^91f372a266fe2bf2823cb8ec7fda31ce\+4',
227             'wrong md5 hash from Keep.put("baz2"): ' + baz_locator)
228         self.assertEqual(keep_client.get(baz_locator),
229                          'baz2',
230                          'wrong content from Keep.get(md5("baz2"))')
231         self.assertTrue(keep_client.using_proxy)
232
233
234 class KeepClientServiceTestCase(unittest.TestCase):
235     def mock_keep_services(self, *services):
236         api_client = mock.MagicMock(name='api_client')
237         api_client.keep_services().accessible().execute.return_value = {
238             'items_available': len(services),
239             'items': [{
240                     'uuid': 'zzzzz-bi6l4-{:015x}'.format(index),
241                     'owner_uuid': 'zzzzz-tpzed-000000000000000',
242                     'service_host': host,
243                     'service_port': port,
244                     'service_ssl_flag': ssl,
245                     'service_type': servtype,
246                     } for index, (host, port, ssl, servtype)
247                       in enumerate(services)],
248             }
249         return api_client
250
251     def mock_n_keep_disks(self, service_count):
252         return self.mock_keep_services(
253             *[("keep0x{:x}".format(index), 80, False, 'disk')
254               for index in range(service_count)])
255
256     def get_service_roots(self, *services):
257         api_client = self.mock_keep_services(*services)
258         keep_client = arvados.KeepClient(api_client=api_client)
259         services = keep_client.weighted_service_roots('000000')
260         return [urlparse.urlparse(url) for url in sorted(services)]
261
262     def test_ssl_flag_respected_in_roots(self):
263         services = self.get_service_roots(('keep', 10, False, 'disk'),
264                                           ('keep', 20, True, 'disk'))
265         self.assertEqual(10, services[0].port)
266         self.assertEqual('http', services[0].scheme)
267         self.assertEqual(20, services[1].port)
268         self.assertEqual('https', services[1].scheme)
269
270     def test_correct_ports_with_ipv6_addresses(self):
271         service = self.get_service_roots(('100::1', 10, True, 'proxy'))[0]
272         self.assertEqual('100::1', service.hostname)
273         self.assertEqual(10, service.port)
274
275     # test_get_timeout and test_put_timeout test that
276     # KeepClient.get and KeepClient.put use the appropriate timeouts
277     # when connected directly to a Keep server (i.e. non-proxy timeout)
278
279     def test_get_timeout(self):
280         api_client = self.mock_keep_services(('keep', 10, False, 'disk'))
281         keep_client = arvados.KeepClient(api_client=api_client)
282         force_timeout = [socket.timeout("timed out")]
283         with mock.patch('requests.get', side_effect=force_timeout) as mock_request:
284             with self.assertRaises(arvados.errors.KeepReadError):
285                 keep_client.get('ffffffffffffffffffffffffffffffff')
286             self.assertTrue(mock_request.called)
287             self.assertEqual(
288                 arvados.KeepClient.DEFAULT_TIMEOUT,
289                 mock_request.call_args[1]['timeout'])
290
291     def test_put_timeout(self):
292         api_client = self.mock_keep_services(('keep', 10, False, 'disk'))
293         keep_client = arvados.KeepClient(api_client=api_client)
294         force_timeout = [socket.timeout("timed out")]
295         with mock.patch('requests.put', side_effect=force_timeout) as mock_request:
296             with self.assertRaises(arvados.errors.KeepWriteError):
297                 keep_client.put('foo')
298             self.assertTrue(mock_request.called)
299             self.assertEqual(
300                 arvados.KeepClient.DEFAULT_TIMEOUT,
301                 mock_request.call_args[1]['timeout'])
302
303     def test_proxy_get_timeout(self):
304         # Force a timeout, verifying that the requests.get or
305         # requests.put method was called with the proxy_timeout
306         # setting rather than the default timeout.
307         api_client = self.mock_keep_services(('keep', 10, False, 'proxy'))
308         keep_client = arvados.KeepClient(api_client=api_client)
309         force_timeout = [socket.timeout("timed out")]
310         with mock.patch('requests.get', side_effect=force_timeout) as mock_request:
311             with self.assertRaises(arvados.errors.KeepReadError):
312                 keep_client.get('ffffffffffffffffffffffffffffffff')
313             self.assertTrue(mock_request.called)
314             self.assertEqual(
315                 arvados.KeepClient.DEFAULT_PROXY_TIMEOUT,
316                 mock_request.call_args[1]['timeout'])
317
318     def test_proxy_put_timeout(self):
319         # Force a timeout, verifying that the requests.get or
320         # requests.put method was called with the proxy_timeout
321         # setting rather than the default timeout.
322         api_client = self.mock_keep_services(('keep', 10, False, 'proxy'))
323         keep_client = arvados.KeepClient(api_client=api_client)
324         force_timeout = [socket.timeout("timed out")]
325         with mock.patch('requests.put', side_effect=force_timeout) as mock_request:
326             with self.assertRaises(arvados.errors.KeepWriteError):
327                 keep_client.put('foo')
328             self.assertTrue(mock_request.called)
329             self.assertEqual(
330                 arvados.KeepClient.DEFAULT_PROXY_TIMEOUT,
331                 mock_request.call_args[1]['timeout'])
332
333     def test_probe_order_reference_set(self):
334         # expected_order[i] is the probe order for
335         # hash=md5(sprintf("%064x",i)) where there are 16 services
336         # with uuid sprintf("anything-%015x",j) with j in 0..15. E.g.,
337         # the first probe for the block consisting of 64 "0"
338         # characters is the service whose uuid is
339         # "zzzzz-bi6l4-000000000000003", so expected_order[0][0]=='3'.
340         expected_order = [
341             list('3eab2d5fc9681074'),
342             list('097dba52e648f1c3'),
343             list('c5b4e023f8a7d691'),
344             list('9d81c02e76a3bf54'),
345             ]
346         hashes = [
347             hashlib.md5("{:064x}".format(x)).hexdigest()
348             for x in range(len(expected_order))]
349         api_client = self.mock_n_keep_disks(16)
350         keep_client = arvados.KeepClient(api_client=api_client)
351         for i, hash in enumerate(hashes):
352             roots = keep_client.weighted_service_roots(hash)
353             got_order = [
354                 re.search(r'//\[?keep0x([0-9a-f]+)', root).group(1)
355                 for root in roots]
356             self.assertEqual(expected_order[i], got_order)
357
358     def test_probe_waste_adding_one_server(self):
359         hashes = [
360             hashlib.md5("{:064x}".format(x)).hexdigest() for x in range(100)]
361         initial_services = 12
362         api_client = self.mock_n_keep_disks(initial_services)
363         keep_client = arvados.KeepClient(api_client=api_client)
364         probes_before = [
365             keep_client.weighted_service_roots(hash) for hash in hashes]
366         for added_services in range(1, 12):
367             api_client = self.mock_n_keep_disks(initial_services+added_services)
368             keep_client = arvados.KeepClient(api_client=api_client)
369             total_penalty = 0
370             for hash_index in range(len(hashes)):
371                 probe_after = keep_client.weighted_service_roots(
372                     hashes[hash_index])
373                 penalty = probe_after.index(probes_before[hash_index][0])
374                 self.assertLessEqual(penalty, added_services)
375                 total_penalty += penalty
376             # Average penalty per block should not exceed
377             # N(added)/N(orig) by more than 20%, and should get closer
378             # to the ideal as we add data points.
379             expect_penalty = (
380                 added_services *
381                 len(hashes) / initial_services)
382             max_penalty = (
383                 expect_penalty *
384                 (120 - added_services)/100)
385             min_penalty = (
386                 expect_penalty * 8/10)
387             self.assertTrue(
388                 min_penalty <= total_penalty <= max_penalty,
389                 "With {}+{} services, {} blocks, penalty {} but expected {}..{}".format(
390                     initial_services,
391                     added_services,
392                     len(hashes),
393                     total_penalty,
394                     min_penalty,
395                     max_penalty))
396
397
398 class KeepClientRetryTestMixin(object):
399     # Testing with a local Keep store won't exercise the retry behavior.
400     # Instead, our strategy is:
401     # * Create a client with one proxy specified (pointed at a black
402     #   hole), so there's no need to instantiate an API client, and
403     #   all HTTP requests come from one place.
404     # * Mock httplib's request method to provide simulated responses.
405     # This lets us test the retry logic extensively without relying on any
406     # supporting servers, and prevents side effects in case something hiccups.
407     # To use this mixin, define DEFAULT_EXPECT, DEFAULT_EXCEPTION, and
408     # run_method().
409     #
410     # Test classes must define TEST_PATCHER to a method that mocks
411     # out appropriate methods in the client.
412
413     PROXY_ADDR = 'http://[%s]:65535/' % (tutil.TEST_HOST,)
414     TEST_DATA = 'testdata'
415     TEST_LOCATOR = 'ef654c40ab4f1747fc699915d4f70902+8'
416
417     def setUp(self):
418         self.client_kwargs = {'proxy': self.PROXY_ADDR, 'local_store': ''}
419
420     def new_client(self, **caller_kwargs):
421         kwargs = self.client_kwargs.copy()
422         kwargs.update(caller_kwargs)
423         return arvados.KeepClient(**kwargs)
424
425     def run_method(self, *args, **kwargs):
426         raise NotImplementedError("test subclasses must define run_method")
427
428     def check_success(self, expected=None, *args, **kwargs):
429         if expected is None:
430             expected = self.DEFAULT_EXPECT
431         self.assertEqual(expected, self.run_method(*args, **kwargs))
432
433     def check_exception(self, error_class=None, *args, **kwargs):
434         if error_class is None:
435             error_class = self.DEFAULT_EXCEPTION
436         self.assertRaises(error_class, self.run_method, *args, **kwargs)
437
438     def test_immediate_success(self):
439         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 200):
440             self.check_success()
441
442     def test_retry_then_success(self):
443         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 500, 200):
444             self.check_success(num_retries=3)
445
446     def test_no_default_retry(self):
447         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 500, 200):
448             self.check_exception()
449
450     def test_no_retry_after_permanent_error(self):
451         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 403, 200):
452             self.check_exception(num_retries=3)
453
454     def test_error_after_retries_exhausted(self):
455         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 500, 500, 200):
456             self.check_exception(num_retries=1)
457
458     def test_num_retries_instance_fallback(self):
459         self.client_kwargs['num_retries'] = 3
460         with self.TEST_PATCHER(self.DEFAULT_EXPECT, 500, 200):
461             self.check_success()
462
463
464 @tutil.skip_sleep
465 class KeepClientRetryGetTestCase(KeepClientRetryTestMixin, unittest.TestCase):
466     DEFAULT_EXPECT = KeepClientRetryTestMixin.TEST_DATA
467     DEFAULT_EXCEPTION = arvados.errors.KeepReadError
468     HINTED_LOCATOR = KeepClientRetryTestMixin.TEST_LOCATOR + '+K@xyzzy'
469     TEST_PATCHER = staticmethod(tutil.mock_get_responses)
470
471     def run_method(self, locator=KeepClientRetryTestMixin.TEST_LOCATOR,
472                    *args, **kwargs):
473         return self.new_client().get(locator, *args, **kwargs)
474
475     def test_specific_exception_when_not_found(self):
476         with tutil.mock_get_responses(self.DEFAULT_EXPECT, 404, 200):
477             self.check_exception(arvados.errors.NotFoundError, num_retries=3)
478
479     def test_general_exception_with_mixed_errors(self):
480         # get should raise a NotFoundError if no server returns the block,
481         # and a high threshold of servers report that it's not found.
482         # This test rigs up 50/50 disagreement between two servers, and
483         # checks that it does not become a NotFoundError.
484         client = self.new_client()
485         with tutil.mock_get_responses(self.DEFAULT_EXPECT, 404, 500):
486             with self.assertRaises(arvados.errors.KeepReadError) as exc_check:
487                 client.get(self.HINTED_LOCATOR)
488             self.assertNotIsInstance(
489                 exc_check.exception, arvados.errors.NotFoundError,
490                 "mixed errors raised NotFoundError")
491
492     def test_hint_server_can_succeed_without_retries(self):
493         with tutil.mock_get_responses(self.DEFAULT_EXPECT, 404, 200, 500):
494             self.check_success(locator=self.HINTED_LOCATOR)
495
496     def test_try_next_server_after_timeout(self):
497         side_effects = [
498             socket.timeout("timed out"),
499             tutil.fake_requests_response(200, self.DEFAULT_EXPECT)]
500         with mock.patch('requests.get',
501                         side_effect=iter(side_effects)):
502             self.check_success(locator=self.HINTED_LOCATOR)
503
504     def test_retry_data_with_wrong_checksum(self):
505         side_effects = (tutil.fake_requests_response(200, s)
506                         for s in ['baddata', self.TEST_DATA])
507         with mock.patch('requests.get', side_effect=side_effects):
508             self.check_success(locator=self.HINTED_LOCATOR)
509
510
511 @tutil.skip_sleep
512 class KeepClientRetryPutTestCase(KeepClientRetryTestMixin, unittest.TestCase):
513     DEFAULT_EXPECT = KeepClientRetryTestMixin.TEST_LOCATOR
514     DEFAULT_EXCEPTION = arvados.errors.KeepWriteError
515     TEST_PATCHER = staticmethod(tutil.mock_put_responses)
516
517     def run_method(self, data=KeepClientRetryTestMixin.TEST_DATA,
518                    copies=1, *args, **kwargs):
519         return self.new_client().put(data, copies, *args, **kwargs)
520
521     def test_do_not_send_multiple_copies_to_same_server(self):
522         with tutil.mock_put_responses(self.DEFAULT_EXPECT, 200):
523             self.check_exception(copies=2, num_retries=3)