Files
seaweedfs/weed/s3api/auth_credentials_subscribe_test.go
T
Chris Lu 5ff49909a0 fix(s3api/iam): avoid transient AccessDenied from full reloads on single IAM file changes (#11271)
* fix(s3api/iam): fail config snapshot on empty or malformed IAM files

A full IAM reload reads every identity/policy/service-account/group file
from the filer. When an external secrets tool rewrites a file, a reload
that reads it mid-rewrite sees empty or partially-written content. The
identity, policy and service-account loaders silently skipped such files
(``continue``), so the snapshot was missing entries that still existed
on disk. The atomic swap then installed an incomplete identity set while
``isAuthEnabled`` stayed on, denying unrelated clients mid-reload
(#11259).

The group loader and the read-error paths already fail the snapshot in
this situation (a skipped entry reads as deleted). Apply the same
behavior to empty content and unmarshal failures across the identity,
policy, service-account and group loaders, so a transient mid-rewrite
fails the reload (preserving the last known-good state) instead of
silently dropping entries.

* fix(s3api/iam): coalesce burst IAM config reloads through the reload queue

onIamConfigChange did a full synchronous reload for every identity/policy
file change event. When several independently-refreshing credentials
rewrite their files within the same second, that produced a burst of
dozens of back-to-back full reloads, each reading the whole store and
widening the window where a mid-rewrite file is observed (#11259).

Route every IAM config change through the existing coalescing reload
queue (scheduleReload/reloadRetryLoop) instead. A burst of N events now
collapses into a single reload (plus one tail reload for events that
arrived while one was in flight). scheduleReload gains a reason argument
for the existing log line; the reloadRetryLoop already retries failed
reloads, so the per-event failure handoff is no longer needed.

Tests that asserted on the synchronous reload now wire up the queue
(centralized in newTestS3ApiServerWithMemoryIAM) and poll via
waitForIdentity/waitForIdentityGone. Adds TestOnIamConfigChangeCoalescesBurstReloads
showing 50 events coalesce into <=3 reloads.

* fix(s3api/iam): skip non-JSON auxiliary files before failing IAM snapshot

Per review: the multi-file loaders unmarshal every entry in an IAM
directory, so a non-JSON auxiliary file (README, .DS_Store, a migration
backup such as identity.json.old) would hit the new empty/malformed
errors and reject the whole snapshot, blocking all later IAM reloads.

Only *.json files are IAM objects (SeaweedFS writes identities,
policies, service accounts and groups as <name>.json, and other call
sites already gate on the .json suffix). Skip non-.json entries at the
top of each loader loop, before reading content, so auxiliary files are
ignored while empty/malformed .json files still fail the snapshot.

Adds TestLoadConfigurationIgnoresNonJsonAuxiliaryFiles.

* fix(s3api/iam): reject IAM files with empty identifiers and skip aux in listing

Per review:

- ListPolicyNames listed every regular entry in the policies directory as a
  policy name, including non-JSON auxiliary files, but GetPolicy cannot
  retrieve them. Apply the same .json suffix filter used by the loader so
  the list only exposes retrievable policies.

- json.Unmarshal accepts `{}` and unknown fields. The identity and group
  loaders merge by the decoded Name (not the file name), so a `{}` file
  could install an empty-key record and displace a real one; the
  service-account loader accepted an empty Id. Validate Identity.Name,
  Group.Name and ServiceAccount.Id (via validateServiceAccountId) after
  unmarshal and fail the snapshot on empty identifiers.

Adds TestFilerEtcStoreListPolicyNamesSkipsNonJsonAuxiliary and
empty-identifier regression tests for identity, group and service-account
files.
2026-09-11 10:42:19 -07:00

203 lines
5.7 KiB
Go

package s3api
import (
"context"
"fmt"
"sync"
"sync/atomic"
"testing"
"time"
"github.com/seaweedfs/seaweedfs/weed/credential"
_ "github.com/seaweedfs/seaweedfs/weed/credential/memory"
"github.com/seaweedfs/seaweedfs/weed/filer"
"github.com/seaweedfs/seaweedfs/weed/pb/filer_pb"
"github.com/seaweedfs/seaweedfs/weed/pb/iam_pb"
)
func TestOnIamConfigChangeLegacyIdentityDeletionReloadsConfiguration(t *testing.T) {
s3a := newTestS3ApiServerWithMemoryIAM(t, []*iam_pb.Identity{
{
Name: "anonymous",
Actions: []string{
"Read:test",
},
},
})
err := s3a.onIamConfigChange(
filer.IamConfigDirectory,
&filer_pb.Entry{Name: filer.IamIdentityFile},
nil,
)
if err != nil {
t.Fatalf("onIamConfigChange returned error for legacy identity deletion: %v", err)
}
if !hasIdentity(s3a.iam, "anonymous") {
t.Fatalf("expected anonymous identity to remain loaded after legacy identity deletion event")
}
}
func TestOnIamConfigChangeReloadsOnIamIdentityDirectoryChanges(t *testing.T) {
s3a := newTestS3ApiServerWithMemoryIAM(t, []*iam_pb.Identity{
{Name: "anonymous"},
})
// Seed initial in-memory IAM state.
if err := s3a.iam.LoadS3ApiConfigurationFromCredentialManager(); err != nil {
t.Fatalf("failed to load initial IAM configuration: %v", err)
}
if hasIdentity(s3a.iam, "alice") {
t.Fatalf("did not expect alice identity before creating user")
}
if err := s3a.iam.credentialManager.CreateUser(context.Background(), &iam_pb.Identity{Name: "alice"}); err != nil {
t.Fatalf("failed to create alice in memory credential manager: %v", err)
}
if err := s3a.onIamConfigChange(
filer.IamConfigDirectory+"/identities",
nil,
&filer_pb.Entry{Name: "alice.json"},
); err != nil {
t.Fatalf("onIamConfigChange returned error for identities directory update: %v", err)
}
waitForIdentity(t, s3a.iam, "alice")
}
func newTestS3ApiServerWithMemoryIAM(t *testing.T, identities []*iam_pb.Identity) *S3ApiServer {
t.Helper()
// Create S3ApiConfiguration for test with provided identities
config := &iam_pb.S3ApiConfiguration{
Identities: identities,
Accounts: []*iam_pb.Account{},
ServiceAccounts: []*iam_pb.ServiceAccount{},
}
// Create memory credential manager
cm, err := credential.NewCredentialManager(credential.StoreTypeMemory, nil, "")
if err != nil {
t.Fatalf("failed to create memory credential manager: %v", err)
}
// Save test configuration
if err := cm.SaveConfiguration(context.Background(), config); err != nil {
t.Fatalf("failed to save test configuration: %v", err)
}
// Create a test IAM instance
iam := &IdentityAccessManagement{
m: sync.RWMutex{},
nameToIdentity: make(map[string]*Identity),
accessKeyIdent: make(map[string]*Identity),
identities: []*Identity{},
policies: make(map[string]*iam_pb.Policy),
accounts: make(map[string]*Account),
emailAccount: make(map[string]*Account),
hashes: make(map[string]*sync.Pool),
hashCounters: make(map[string]*int32),
isAuthEnabled: false,
stopChan: make(chan struct{}),
reloadCh: make(chan struct{}, 1),
useStaticConfig: false,
credentialManager: cm,
}
go iam.reloadRetryLoop()
t.Cleanup(iam.Shutdown)
// Load test configuration
if err := iam.ReplaceS3ApiConfiguration(config); err != nil {
t.Fatalf("failed to load test configuration: %v", err)
}
return &S3ApiServer{
iam: iam,
}
}
func hasIdentity(iam *IdentityAccessManagement, identityName string) bool {
iam.m.RLock()
defer iam.m.RUnlock()
_, ok := iam.nameToIdentity[identityName]
return ok
}
func waitForIdentity(t *testing.T, iam *IdentityAccessManagement, name string) {
t.Helper()
deadline := time.Now().Add(5 * time.Second)
for !hasIdentity(iam, name) {
if time.Now().After(deadline) {
t.Fatalf("expected identity %s to be loaded", name)
}
time.Sleep(10 * time.Millisecond)
}
}
func waitForIdentityGone(t *testing.T, iam *IdentityAccessManagement, name string) {
t.Helper()
deadline := time.Now().Add(5 * time.Second)
for hasIdentity(iam, name) {
if time.Now().After(deadline) {
t.Fatalf("expected identity %s to be gone", name)
}
time.Sleep(10 * time.Millisecond)
}
}
// countingStore wraps a store and counts LoadConfiguration calls.
type countingStore struct {
credential.CredentialStore
loads int64
}
func (c *countingStore) LoadConfiguration(ctx context.Context) (*iam_pb.S3ApiConfiguration, error) {
atomic.AddInt64(&c.loads, 1)
return c.CredentialStore.LoadConfiguration(ctx)
}
// A burst of IAM config change events must coalesce into a handful of reloads,
// not one full reload per event.
func TestOnIamConfigChangeCoalescesBurstReloads(t *testing.T) {
s3a := newTestS3ApiServerWithMemoryIAM(t, []*iam_pb.Identity{{Name: "anonymous"}})
counter := &countingStore{CredentialStore: s3a.iam.credentialManager.Store}
s3a.iam.credentialManager.Store = counter
const burst = 50
for i := 0; i < burst; i++ {
if err := s3a.onIamConfigChange(
filer.IamConfigDirectory+"/identities",
nil,
&filer_pb.Entry{Name: fmt.Sprintf("u%d.json", i)},
); err != nil {
t.Fatalf("onIamConfigChange returned error: %v", err)
}
}
// Wait for the queue to drain: no pending signal.
deadline := time.Now().Add(5 * time.Second)
for {
s3a.iam.reloadMu.Lock()
empty := len(s3a.iam.reloadCh) == 0
s3a.iam.reloadMu.Unlock()
if empty {
break
}
if time.Now().After(deadline) {
t.Fatalf("reload queue did not drain")
}
time.Sleep(10 * time.Millisecond)
}
// Let any final coalesced reload finish.
time.Sleep(50 * time.Millisecond)
loads := atomic.LoadInt64(&counter.loads)
if loads > 3 {
t.Fatalf("expected a burst of %d events to coalesce into <=3 reloads, got %d", burst, loads)
}
}