1 // Copyright (C) The Arvados Authors. All rights reserved.
3 // SPDX-License-Identifier: AGPL-3.0
19 "git.arvados.org/arvados.git/sdk/go/arvadosclient"
20 "git.arvados.org/arvados.git/sdk/go/arvadostest"
21 "git.arvados.org/arvados.git/sdk/go/keepclient"
26 // Gocheck boilerplate
27 func Test(t *testing.T) {
31 // Gocheck boilerplate
32 var _ = Suite(&ServerRequiredSuite{})
33 var _ = Suite(&DoMainTestSuite{})
35 type ServerRequiredSuite struct{}
36 type DoMainTestSuite struct{}
38 var kc *keepclient.KeepClient
39 var logBuffer bytes.Buffer
41 var TestHash = "aaaa09c290d0fb1ca068ffaddf22cbd0"
42 var TestHash2 = "aaaac516f788aec4f30932ffb6395c39"
44 var blobSignatureTTL = time.Duration(2*7*24) * time.Hour
46 func (s *ServerRequiredSuite) TearDownSuite(c *C) {
47 arvadostest.ResetEnv()
50 func (s *ServerRequiredSuite) SetUpTest(c *C) {
52 logOutput := io.MultiWriter(&logBuffer)
53 log.SetOutput(logOutput)
56 func (s *ServerRequiredSuite) TearDownTest(c *C) {
57 arvadostest.StopKeep(2)
58 log.SetOutput(os.Stdout)
59 c.Log(logBuffer.String())
62 func (s *DoMainTestSuite) SetUpSuite(c *C) {
65 func (s *DoMainTestSuite) SetUpTest(c *C) {
66 logOutput := io.MultiWriter(&logBuffer)
67 log.SetOutput(logOutput)
68 keepclient.RefreshServiceDiscovery()
71 func (s *DoMainTestSuite) TearDownTest(c *C) {
72 log.SetOutput(os.Stdout)
73 log.Printf("%v", logBuffer.String())
76 func setupKeepBlockCheck(c *C, enforcePermissions bool, keepServicesJSON string) {
77 setupKeepBlockCheckWithTTL(c, enforcePermissions, keepServicesJSON, blobSignatureTTL)
80 func setupKeepBlockCheckWithTTL(c *C, enforcePermissions bool, keepServicesJSON string, ttl time.Duration) {
82 config.APIHost = os.Getenv("ARVADOS_API_HOST")
83 config.APIToken = arvadostest.DataManagerToken
84 config.APIHostInsecure = arvadosclient.StringBool(os.Getenv("ARVADOS_API_HOST_INSECURE"))
87 arvadostest.StartKeep(2, enforcePermissions)
91 kc, ttl, err = setupKeepClient(config, keepServicesJSON, ttl)
92 c.Assert(ttl, Equals, blobSignatureTTL)
95 keepclient.RefreshServiceDiscovery()
99 func setupTestData(c *C) []string {
100 allLocators := []string{}
103 for i := 0; i < 5; i++ {
104 hash, _, err := kc.PutB([]byte(fmt.Sprintf("keep-block-check-test-data-%d", i)))
106 allLocators = append(allLocators, strings.Split(hash, "+A")[0])
112 func setupConfigFile(c *C, fileName string) string {
113 // Setup a config file
114 file, err := ioutil.TempFile(os.TempDir(), fileName)
117 // Add config to file. While at it, throw some extra white space
118 fileContent := "ARVADOS_API_HOST=" + os.Getenv("ARVADOS_API_HOST") + "\n"
119 fileContent += "ARVADOS_API_TOKEN=" + arvadostest.DataManagerToken + "\n"
121 fileContent += "ARVADOS_API_HOST_INSECURE=" + os.Getenv("ARVADOS_API_HOST_INSECURE") + "\n"
122 fileContent += " NotANameValuePairAndShouldGetIgnored \n"
123 fileContent += "ARVADOS_BLOB_SIGNING_KEY=abcdefg\n"
125 _, err = file.Write([]byte(fileContent))
131 func setupBlockHashFile(c *C, name string, blocks []string) string {
132 // Setup a block hash file
133 file, err := ioutil.TempFile(os.TempDir(), name)
136 // Add the hashes to the file. While at it, throw some extra white space
138 for _, hash := range blocks {
139 fileContent += fmt.Sprintf(" %s \n", hash)
142 _, err = file.Write([]byte(fileContent))
148 func checkErrorLog(c *C, blocks []string, prefix, suffix string) {
149 for _, hash := range blocks {
150 expected := `(?ms).*` + prefix + `.*` + hash + `.*` + suffix + `.*`
151 c.Check(logBuffer.String(), Matches, expected)
155 func checkNoErrorsLogged(c *C, prefix, suffix string) {
156 expected := prefix + `.*` + suffix
157 match, _ := regexp.MatchString(expected, logBuffer.String())
158 c.Assert(match, Equals, false)
161 func (s *ServerRequiredSuite) TestBlockCheck(c *C) {
162 setupKeepBlockCheck(c, false, "")
163 allLocators := setupTestData(c)
164 err := performKeepBlockCheck(kc, blobSignatureTTL, "", allLocators, true)
166 checkNoErrorsLogged(c, "Error verifying block", "Block not found")
169 func (s *ServerRequiredSuite) TestBlockCheckWithBlobSigning(c *C) {
170 setupKeepBlockCheck(c, true, "")
171 allLocators := setupTestData(c)
172 err := performKeepBlockCheck(kc, blobSignatureTTL, arvadostest.BlobSigningKey, allLocators, true)
174 checkNoErrorsLogged(c, "Error verifying block", "Block not found")
177 func (s *ServerRequiredSuite) TestBlockCheckWithBlobSigningAndTTLFromDiscovery(c *C) {
178 setupKeepBlockCheckWithTTL(c, true, "", 0)
179 allLocators := setupTestData(c)
180 err := performKeepBlockCheck(kc, blobSignatureTTL, arvadostest.BlobSigningKey, allLocators, true)
182 checkNoErrorsLogged(c, "Error verifying block", "Block not found")
185 func (s *ServerRequiredSuite) TestBlockCheck_NoSuchBlock(c *C) {
186 setupKeepBlockCheck(c, false, "")
187 allLocators := setupTestData(c)
188 allLocators = append(allLocators, TestHash)
189 allLocators = append(allLocators, TestHash2)
190 err := performKeepBlockCheck(kc, blobSignatureTTL, "", allLocators, true)
192 c.Assert(err.Error(), Equals, "Block verification failed for 2 out of 7 blocks with matching prefix")
193 checkErrorLog(c, []string{TestHash, TestHash2}, "Error verifying block", "Block not found")
196 func (s *ServerRequiredSuite) TestBlockCheck_NoSuchBlock_WithMatchingPrefix(c *C) {
197 setupKeepBlockCheck(c, false, "")
198 allLocators := setupTestData(c)
199 allLocators = append(allLocators, TestHash)
200 allLocators = append(allLocators, TestHash2)
201 locatorFile := setupBlockHashFile(c, "block-hash", allLocators)
202 defer os.Remove(locatorFile)
203 locators, err := getBlockLocators(locatorFile, "aaa")
205 err = performKeepBlockCheck(kc, blobSignatureTTL, "", locators, true)
207 // Of the 7 blocks in allLocators, only two match the prefix and hence only those are checked
208 c.Assert(err.Error(), Equals, "Block verification failed for 2 out of 2 blocks with matching prefix")
209 checkErrorLog(c, []string{TestHash, TestHash2}, "Error verifying block", "Block not found")
212 func (s *ServerRequiredSuite) TestBlockCheck_NoSuchBlock_WithPrefixMismatch(c *C) {
213 setupKeepBlockCheck(c, false, "")
214 allLocators := setupTestData(c)
215 allLocators = append(allLocators, TestHash)
216 allLocators = append(allLocators, TestHash2)
217 locatorFile := setupBlockHashFile(c, "block-hash", allLocators)
218 defer os.Remove(locatorFile)
219 locators, err := getBlockLocators(locatorFile, "999")
221 err = performKeepBlockCheck(kc, blobSignatureTTL, "", locators, true)
222 c.Check(err, IsNil) // there were no matching locators in file and hence nothing was checked
225 func (s *ServerRequiredSuite) TestBlockCheck_BadSignature(c *C) {
226 setupKeepBlockCheck(c, true, "")
228 err := performKeepBlockCheck(kc, blobSignatureTTL, "badblobsigningkey", []string{TestHash, TestHash2}, false)
229 c.Assert(err.Error(), Equals, "Block verification failed for 2 out of 2 blocks with matching prefix")
230 // older versions of keepstore return 403 Forbidden for
231 // invalid signatures, newer versions return 400 Bad Request.
232 checkErrorLog(c, []string{TestHash, TestHash2}, "Error verifying block", "HTTP 40[03]")
233 // verbose logging not requested
234 c.Assert(strings.Contains(logBuffer.String(), "Verifying block 1 of 2"), Equals, false)
237 var testKeepServicesJSON = `{
238 "kind":"arvados#keepServiceList",
241 "offset":null, "limit":null,
243 {"href":"/keep_services/zzzzz-bi6l4-123456789012340",
244 "kind":"arvados#keepService",
245 "uuid":"zzzzz-bi6l4-123456789012340",
246 "service_host":"keep0.zzzzz.arvadosapi.com",
247 "service_port":25107,
248 "service_ssl_flag":false,
249 "service_type":"disk",
251 {"href":"/keep_services/zzzzz-bi6l4-123456789012341",
252 "kind":"arvados#keepService",
253 "uuid":"zzzzz-bi6l4-123456789012341",
254 "service_host":"keep0.zzzzz.arvadosapi.com",
255 "service_port":25108,
256 "service_ssl_flag":false,
257 "service_type":"disk",
260 "items_available":2 }`
262 // Setup block-check using keepServicesJSON with fake keepservers.
263 // Expect error during performKeepBlockCheck due to unreachable keepservers.
264 func (s *ServerRequiredSuite) TestErrorDuringKeepBlockCheck_FakeKeepservers(c *C) {
265 setupKeepBlockCheck(c, false, testKeepServicesJSON)
266 err := performKeepBlockCheck(kc, blobSignatureTTL, "", []string{TestHash, TestHash2}, true)
267 c.Assert(err.Error(), Equals, "Block verification failed for 2 out of 2 blocks with matching prefix")
268 checkErrorLog(c, []string{TestHash, TestHash2}, "Error verifying block", "")
271 // Test keep-block-check initialization with keepServicesJSON
272 func (s *ServerRequiredSuite) TestKeepBlockCheck_InitializeWithKeepServicesJSON(c *C) {
273 setupKeepBlockCheck(c, false, testKeepServicesJSON)
275 for k := range kc.LocalRoots() {
276 if k == "zzzzz-bi6l4-123456789012340" || k == "zzzzz-bi6l4-123456789012341" {
280 c.Check(found, Equals, 2)
283 // Test loadConfig func
284 func (s *ServerRequiredSuite) TestLoadConfig(c *C) {
286 configFile := setupConfigFile(c, "config")
287 defer os.Remove(configFile)
289 // load configuration from the file
290 config, blobSigningKey, err := loadConfig(configFile)
293 c.Assert(config.APIHost, Equals, os.Getenv("ARVADOS_API_HOST"))
294 c.Assert(config.APIToken, Equals, arvadostest.DataManagerToken)
295 c.Assert(config.APIHostInsecure, Equals, arvadosclient.StringBool(os.Getenv("ARVADOS_API_HOST_INSECURE")))
296 c.Assert(blobSigningKey, Equals, "abcdefg")
299 func (s *DoMainTestSuite) Test_doMain_WithNoConfig(c *C) {
300 args := []string{"-prefix", "a"}
301 var stderr bytes.Buffer
302 code := doMain(args, &stderr)
303 c.Check(code, Equals, 1)
304 c.Check(stderr.String(), Matches, ".*config file not specified\n")
307 func (s *DoMainTestSuite) Test_doMain_WithNoSuchConfigFile(c *C) {
308 args := []string{"-config", "no-such-file"}
309 var stderr bytes.Buffer
310 code := doMain(args, &stderr)
311 c.Check(code, Equals, 1)
312 c.Check(stderr.String(), Matches, ".*no such file or directory\n")
315 func (s *DoMainTestSuite) Test_doMain_WithNoBlockHashFile(c *C) {
316 config := setupConfigFile(c, "config")
317 defer os.Remove(config)
319 // Start keepservers.
320 arvadostest.StartKeep(2, false)
321 defer arvadostest.StopKeep(2)
323 args := []string{"-config", config}
324 var stderr bytes.Buffer
325 code := doMain(args, &stderr)
326 c.Check(code, Equals, 1)
327 c.Check(stderr.String(), Matches, ".*block-hash-file not specified\n")
330 func (s *DoMainTestSuite) Test_doMain_WithNoSuchBlockHashFile(c *C) {
331 config := setupConfigFile(c, "config")
332 defer os.Remove(config)
334 arvadostest.StartKeep(2, false)
335 defer arvadostest.StopKeep(2)
337 args := []string{"-config", config, "-block-hash-file", "no-such-file"}
338 var stderr bytes.Buffer
339 code := doMain(args, &stderr)
340 c.Check(code, Equals, 1)
341 c.Check(stderr.String(), Matches, ".*no such file or directory\n")
344 func (s *DoMainTestSuite) Test_doMain(c *C) {
345 // Start keepservers.
346 arvadostest.StartKeep(2, false)
347 defer arvadostest.StopKeep(2)
349 config := setupConfigFile(c, "config")
350 defer os.Remove(config)
352 locatorFile := setupBlockHashFile(c, "block-hash", []string{TestHash, TestHash2})
353 defer os.Remove(locatorFile)
355 args := []string{"-config", config, "-block-hash-file", locatorFile, "-v"}
356 var stderr bytes.Buffer
357 code := doMain(args, &stderr)
358 c.Check(code, Equals, 1)
359 c.Assert(stderr.String(), Matches, "Block verification failed for 2 out of 2 blocks with matching prefix\n")
360 checkErrorLog(c, []string{TestHash, TestHash2}, "Error verifying block", "Block not found")
361 c.Assert(strings.Contains(logBuffer.String(), "Verifying block 1 of 2"), Equals, true)