Viewing: sanity-sec.sh
#!/usr/bin/bash
#
# Run select tests by setting ONLY, or as arguments to the script.
# Skip specific tests by setting EXCEPT.
#
set -e
ONLY=${ONLY:-"$*"}
LUSTRE=${LUSTRE:-$(dirname $0)/..}
. $LUSTRE/tests/test-framework.sh
init_test_env $@
init_logging
ALWAYS_EXCEPT="$SANITY_SEC_EXCEPT "
[[ "$SLOW" == "no" ]] && EXCEPT_SLOW="26"
NODEMAP_TESTS=$(seq 7 26)
if ! check_versions; then
echo "It is NOT necessary to test nodemap under interoperation mode"
EXCEPT="$EXCEPT $NODEMAP_TESTS"
fi
build_test_filter
RUNAS_CMD=${RUNAS_CMD:-runas}
WTL=${WTL:-"$LUSTRE/tests/write_time_limit"}
CONFDIR=/etc/lustre
PERM_CONF=$CONFDIR/perm.conf
FAIL_ON_ERROR=false
HOSTNAME_CHECKSUM=$(hostname | sum | awk '{ print $1 }')
SUBNET_CHECKSUM=$(expr $HOSTNAME_CHECKSUM % 250 + 1)
require_dsh_mds || exit 0
require_dsh_ost || exit 0
clients=${CLIENTS//,/ }
num_clients=$(get_node_count ${clients})
clients_arr=($clients)
echo "was USER0=$(getent passwd | grep :${ID0:-500}:)"
echo "was USER1=$(getent passwd | grep :${ID1:-501}:)"
ID0=$(id -u $USER0)
ID1=$(id -u $USER1)
echo "now USER0=$USER0=$ID0:$(id -g $USER0), USER1=$USER1=$ID1:$(id -g $USER1)"
if [ "$SLOW" == "yes" ]; then
NODEMAP_COUNT=16
NODEMAP_RANGE_COUNT=3
NODEMAP_IPADDR_LIST="1 10 64 128 200 250"
NODEMAP_ID_COUNT=10
else
NODEMAP_COUNT=3
NODEMAP_RANGE_COUNT=2
NODEMAP_IPADDR_LIST="1 250"
NODEMAP_ID_COUNT=3
fi
NODEMAP_MAX_ID=$((ID0 + NODEMAP_ID_COUNT))
[ -z "$USER0" ] &&
skip "need to add user0 ($ID0:$ID0)" && exit 0
[ -z "$USER1" ] &&
skip "need to add user1 ($ID1:$ID1)" && exit 0
IDBASE=${IDBASE:-60000}
# changes to mappings must be reflected in test 23
FOPS_IDMAPS=(
[0]="$((IDBASE+3)):$((IDBASE+0)) $((IDBASE+4)):$((IDBASE+2))"
[1]="$((IDBASE+5)):$((IDBASE+1)) $((IDBASE+6)):$((IDBASE+2))"
)
check_and_setup_lustre
assert_DIR
MDT=$(mdtname_from_index 0 $MOUNT)
[[ -z "$MDT" ]] && error "fail to get MDT0000 device name" && exit 1
do_facet $SINGLEMDS "mkdir -p $CONFDIR"
IDENTITY_FLUSH=mdt.$MDT.identity_flush
SAVE_PWD=$PWD
if (( $MDS1_VERSION >= $(version_code 2.16.51) )); then
nodemap_activate="nodemap activate"
nodemap_new="nodemap add"
nodemap_del="nodemap del"
nodemap_info="nodemap info"
nodemap_modify="nodemap modify"
nodemap_add_range="nodemap add_range"
nodemap_del_range="nodemap del_range"
nodemap_add_idmap="nodemap add_idmap"
nodemap_del_idmap="nodemap del_idmap"
nodemap_test_nid="nodemap test_nid"
nodemap_test_id="nodemap test_id"
nodemap_set_fileset="nodemap set_fileset"
nodemap_set_sepol="nodemap set_sepol"
else
nodemap_activate="nodemap_activate"
nodemap_new="nodemap_add"
nodemap_del="nodemap_del"
nodemap_info="nodemap_info"
nodemap_modify="nodemap_modify"
nodemap_add_range="nodemap_add_range"
nodemap_del_range="nodemap_del_range"
nodemap_add_idmap="nodemap_add_idmap"
nodemap_del_idmap="nodemap_del_idmap"
nodemap_test_nid="nodemap_test_nid"
nodemap_test_id="nodemap_test_id"
nodemap_set_fileset="nodemap_set_fileset"
nodemap_set_sepol="nodemap_set_sepol"
fi
if (( (MDS1_REL > ES7) ||
(MDS1_REL == ES7 && MDS1_VERSION >= $(version_code 2.16.0-ddn40)) ||
(MDS1_REL == ES6 && MDS1_VERSION >= $(version_code 2.14.0-ddn230)) ||
(MDS1_REL == MASTER && MDS1_VERSION >= $(version_code 2.16.61)) )); then
nodemap_new="nodemap new"
fi
sec_login() {
local user=$1
local group=$2
$GSS_KRB5 || return
if ! $RUNAS_CMD -u $user krb5_login.sh; then
error "$user login kerberos failed."
exit 1
fi
if ! $RUNAS_CMD -u $user -g $group ls $DIR > /dev/null 2>&1; then
$RUNAS_CMD -u $user lfs flushctx -k
$RUNAS_CMD -u $user krb5_login.sh
if ! $RUNAS_CMD -u$user -g$group ls $DIR > /dev/null 2>&1; then
error "init $user $group failed."
exit 2
fi
fi
}
declare -a identity_old
wait_ssk() {
# wait for SSK flavor to be applied if necessary
if $GSS_SK; then
if $SK_S2S; then
wait_flavor all2all $SK_FLAVOR
else
wait_flavor cli2mdt $SK_FLAVOR
wait_flavor cli2ost $SK_FLAVOR
fi
fi
}
sec_setup() {
for ((num = 1; num <= $MDSCOUNT; num++)); do
switch_identity $num true || identity_old[$num]=$?
done
if ! $RUNAS_CMD -u $ID0 ls $DIR > /dev/null 2>&1; then
sec_login $USER0 $USER0
fi
if ! $RUNAS_CMD -u $ID1 ls $DIR > /dev/null 2>&1; then
sec_login $USER1 $USER1
fi
wait_ssk
}
sec_setup
# run as different user
test_0() {
umask 0022
chmod 0755 $DIR || error "chmod (1) Failed"
rm -rf $DIR/$tdir || error "rm (1) Failed"
mkdir -p $DIR/$tdir || error "mkdir (1) Failed"
# $DIR/$tdir owner changed to USER0(sanityusr)
chown $USER0 $DIR/$tdir || error "chown (2) Failed"
chmod 0755 $DIR/$tdir || error "chmod (2) Failed"
# Run as ID0 cmd must pass
$RUNAS_CMD -u $ID0 ls -ali $DIR || error "ls (1) Failed"
# Remove non-existing file f0
rm -f $DIR/f0 || error "rm (2) Failed"
# It is expected that this cmd should fail
# $DIR has only r-x rights for group and other
$RUNAS_CMD -u $ID0 touch $DIR/f0
(( $? == 0 )) && error "touch (1) should not pass"
# This must pass. $DIR/$tdir/ is owned by ID0/USER0
$RUNAS_CMD -u $ID0 touch $DIR/$tdir/f1 || error "touch (2) Failed"
# It is expected that this cmd should fail
# $tdir has rwxr-xr-x rights for $ID0
$RUNAS_CMD -u $ID1 touch $DIR/$tdir/f2
(( $? == 0 )) && error "touch (3) should not pass"
touch $DIR/$tdir/f3 || error "touch (4) Failed"
chown root $DIR/$tdir || error "chown (3) Failed"
chgrp $USER0 $DIR/$tdir || error "chgrp (1) Failed"
chmod 0775 $DIR/$tdir || error "chmod (3) Failed"
# Owner is root and group is USER0
$RUNAS_CMD -u $USER0 -g $USER0 touch $DIR/$tdir/f4 ||
error "touch (5) Failed"
# It is expected that this cmd should fail
# $tdir has rwxrwxr-x rights for group sanityusr/ID0, ID1 will fail
$RUNAS_CMD -u $ID1 -g $ID1 touch $DIR/$tdir/f5
(( $? == 0 )) && error "touch (6) should not pass"
touch $DIR/$tdir/f6 || error "touch (7) Failed"
rm -rf $DIR/$tdir || error "rm (3) Failed"
}
run_test 0 "uid permission ============================="
# setuid/gid
test_1() {
$GSS || skip "without GSS support."
rm -rf $DIR/$tdir
mkdir_on_mdt0 $DIR/$tdir
chown $USER0 $DIR/$tdir || error "chown (1)"
$RUNAS_CMD -u $ID1 -v $ID0 touch $DIR/$tdir/f0 && error "touch (2)"
echo "enable uid $ID1 setuid"
do_facet $SINGLEMDS "echo '* $ID1 setuid' >> $PERM_CONF"
do_facet $SINGLEMDS "lctl set_param -n $IDENTITY_FLUSH=-1"
$RUNAS_CMD -u $ID1 -v $ID0 touch $DIR/$tdir/f1 || error "touch (3)"
chown root $DIR/$tdir || error "chown (4)"
chgrp $USER0 $DIR/$tdir || error "chgrp (5)"
chmod 0770 $DIR/$tdir || error "chmod (6)"
$RUNAS_CMD -u $ID1 -g $ID1 touch $DIR/$tdir/f2 && error "touch (7)"
$RUNAS_CMD -u$ID1 -g$ID1 -j$ID0 touch $DIR/$tdir/f3 && error "touch (8)"
echo "enable uid $ID1 setuid,setgid"
do_facet $SINGLEMDS "echo '* $ID1 setuid,setgid' > $PERM_CONF"
do_facet $SINGLEMDS "lctl set_param -n $IDENTITY_FLUSH=-1"
$RUNAS_CMD -u $ID1 -g $ID1 -j $ID0 touch $DIR/$tdir/f4 ||
error "touch (9)"
$RUNAS_CMD -u $ID1 -v $ID0 -g $ID1 -j $ID0 touch $DIR/$tdir/f5 ||
error "touch (10)"
rm -rf $DIR/$tdir
do_facet $SINGLEMDS "rm -f $PERM_CONF"
do_facet $SINGLEMDS "lctl set_param -n $IDENTITY_FLUSH=-1"
}
run_test 1 "setuid/gid ============================="
# bug 3285 - supplementary group should always succeed.
# NB: the supplementary groups are set for local client only,
# as for remote client, the groups of the specified uid on MDT
# will be obtained by upcall /usr/sbin/l_getidentity and used.
test_4() {
[[ "$MDS1_VERSION" -ge $(version_code 2.6.93) ]] ||
[[ "$MDS1_VERSION" -ge $(version_code 2.5.35) &&
"$MDS1_VERSION" -lt $(version_code 2.5.50) ]] ||
skip "Need MDS version at least 2.6.93 or 2.5.35"
rm -rf $DIR/$tdir
mkdir_on_mdt0 -p $DIR/$tdir
chmod 0771 $DIR/$tdir
chgrp $ID0 $DIR/$tdir
$RUNAS_CMD -u $ID0 ls $DIR/$tdir || error "setgroups (1)"
do_facet $SINGLEMDS "echo '* $ID1 setgrp' > $PERM_CONF"
do_facet $SINGLEMDS "lctl set_param -n $IDENTITY_FLUSH=-1"
$RUNAS_CMD -u $ID1 -G1,2,$ID0 ls $DIR/$tdir ||
error "setgroups (2)"
$RUNAS_CMD -u $ID1 -G1,2 ls $DIR/$tdir && error "setgroups (3)"
rm -rf $DIR/$tdir
do_facet $SINGLEMDS "rm -f $PERM_CONF"
do_facet $SINGLEMDS "lctl set_param -n $IDENTITY_FLUSH=-1"
}
run_test 4 "set supplementary group ==============="
test_5() {
local num
local uid
remote_mds || skip_env "needs remote MDS"
for ((num = 1; num < 500; num++)); do
uid=$((RANDOM * RANDOM))
do_facet $SINGLEMDS "getent passwd $uid" || break
done
(( num == 500 )) &&
skip_env "cannot find a nonexistent user on $SINGLEMDS"
do_facet $SINGLEMDS "$LCTL set_param -n $IDENTITY_FLUSH=-1"
cancel_lru_locks
# This cmd should fail because $uid doesn't exist on MGS
$RUNAS_CMD -u $uid ls $DIR && error "ls should fail as $uid"
# Check log on the MDT
do_facet $SINGLEMDS "journalctl -t l_getidentity \
--since '1 minute ago' |
grep -A1 'no such user $uid' |
grep -B1 'write ret -1: Identifier removed'" ||
error "l_getidentity threw unexpected return value or errno"
}
run_test 5 "Test l_getidentity with a nonexistent user on the MDT"
create_nodemaps() {
local csum
local i
local rc
squash_id default ${NOBODY_UID:-65534} 0
wait_nm_sync default squash_uid '' inactive
squash_id default ${NOBODY_UID:-65534} 1
wait_nm_sync default squash_gid '' inactive
for (( i = 0; i < NODEMAP_COUNT; i++ )); do
csum=${HOSTNAME_CHECKSUM}_${i}
do_facet mgs $LCTL $nodemap_new $csum
rc=$?
if [ $rc -ne 0 ]; then
echo "$nodemap_new $csum failed with $rc"
return $rc
fi
wait_update_facet --verbose mgs \
"$LCTL get_param nodemap.$csum.id 2>/dev/null | \
grep -c $csum || true" 1 30 ||
return 1
done
# it is enough to check and wait for the last nodemap
csum=${HOSTNAME_CHECKSUM}_$((NODEMAP_COUNT - 1))
wait_nm_sync $csum id '' inactive
return 0
}
delete_nodemaps() {
local csum
local i
for ((i = 0; i < NODEMAP_COUNT; i++)); do
csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $LCTL $nodemap_del $csum; then
error "$nodemap_del $csum failed with $?"
return 3
fi
wait_update_facet --verbose mgs \
"$LCTL get_param nodemap.$csum.id 2>/dev/null | \
grep -c $csum || true" 0 30 ||
return 1
done
# it is enough to check and wait for the last nodemap
csum=${HOSTNAME_CHECKSUM}_$((NODEMAP_COUNT - 1))
wait_nm_sync $csum id '' inactive
return 0
}
add_range() {
local j
local cmd="$LCTL $nodemap_add_range"
local range
local rc=0
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
range="$SUBNET_CHECKSUM.${2}.${j}.[1-253]@tcp"
if ! do_facet mgs $cmd --name $1 --range $range; then
rc=$((rc + 1))
fi
done
return $rc
}
delete_range() {
local j
local cmd="$LCTL $nodemap_del_range"
local range
local rc=0
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
range="$SUBNET_CHECKSUM.${2}.${j}.[1-253]@tcp"
if ! do_facet mgs $cmd --name $1 --range $range; then
rc=$((rc + 1))
fi
done
return $rc
}
add_idmaps() {
local i
local cmd="$LCTL $nodemap_add_idmap"
local do_proj=true
local rc=0
(( $MDS1_VERSION >= $(version_code 2.14.52) )) || do_proj=false
echo "Start to add idmaps ..."
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local j
for ((j = $ID0; j < NODEMAP_MAX_ID; j++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
local client_id=$j
local fs_id=$((j + 1))
if ! do_facet mgs $cmd --name $csum --idtype uid \
--idmap $client_id:$fs_id; then
rc=$((rc + 1))
fi
if ! do_facet mgs $cmd --name $csum --idtype gid \
--idmap $client_id:$fs_id; then
rc=$((rc + 1))
fi
if $do_proj; then
if ! do_facet mgs $cmd --name $csum \
--idtype projid --idmap \
$client_id:$fs_id; then
rc=$((rc + 1))
fi
fi
done
done
return $rc
}
add_root_idmaps() {
local i
local cmd="$LCTL $nodemap_add_idmap"
local rc=0
echo "Start to add root idmaps ..."
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $cmd --name $csum --idtype uid \
--idmap 0:1; then
rc=$((rc + 1))
fi
if ! do_facet mgs $cmd --name $csum --idtype gid \
--idmap 0:1; then
rc=$((rc + 1))
fi
done
return $rc
}
update_idmaps() { #LU-10040
[ "$MGS_VERSION" -lt $(version_code 2.10.55) ] &&
skip "Need MGS >= 2.10.55"
local csum=${HOSTNAME_CHECKSUM}_0
local old_id_client=$ID0
local old_id_fs=$((ID0 + 1))
local new_id=$((ID0 + 100))
local tmp_id
local cmd
local rc=0
echo "Start to update idmaps ..."
#Inserting an existed idmap should return error
cmd="$LCTL $nodemap_add_idmap --name $csum --idtype uid"
if do_facet mgs \
$cmd --idmap $old_id_client:$old_id_fs 2>/dev/null; then
error "insert idmap {$old_id_client:$old_id_fs} " \
"should return error"
rc=$((rc + 1))
return rc
fi
#Update id_fs and check it
if ! do_facet mgs $cmd --idmap $old_id_client:$new_id; then
error "$cmd --idmap $old_id_client:$new_id failed"
rc=$((rc + 1))
return $rc
fi
tmp_id=$(do_facet mgs $LCTL get_param -n nodemap.$csum.idmap |
awk '{ print $7 }' | sed -n '2p')
[ $tmp_id != $new_id ] && { error "new id_fs $tmp_id != $new_id"; \
rc=$((rc + 1)); return $rc; }
#Update id_client and check it
if ! do_facet mgs $cmd --idmap $new_id:$new_id; then
error "$cmd --idmap $new_id:$new_id failed"
rc=$((rc + 1))
return $rc
fi
tmp_id=$(do_facet mgs $LCTL get_param -n nodemap.$csum.idmap |
awk '{ print $5 }' | sed -n "$((NODEMAP_ID_COUNT + 1)) p")
tmp_id=$(echo ${tmp_id%,*}) #e.g. "501,"->"501"
[ $tmp_id != $new_id ] && { error "new id_client $tmp_id != $new_id"; \
rc=$((rc + 1)); return $rc; }
#Delete above updated idmap
cmd="$LCTL $nodemap_del_idmap --name $csum --idtype uid"
if ! do_facet mgs $cmd --idmap $new_id:$new_id; then
error "$cmd --idmap $new_id:$new_id failed"
rc=$((rc + 1))
return $rc
fi
#restore the idmaps to make delete_idmaps work well
cmd="$LCTL $nodemap_add_idmap --name $csum --idtype uid"
if ! do_facet mgs $cmd --idmap $old_id_client:$old_id_fs; then
error "$cmd --idmap $old_id_client:$old_id_fs failed"
rc=$((rc + 1))
return $rc
fi
return $rc
}
delete_idmaps() {
local i
local cmd="$LCTL $nodemap_del_idmap"
local do_proj=true
local rc=0
(( $MDS1_VERSION >= $(version_code 2.14.52) )) || do_proj=false
echo "Start to delete idmaps ..."
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local j
for ((j = $ID0; j < NODEMAP_MAX_ID; j++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
local client_id=$j
local fs_id=$((j + 1))
if ! do_facet mgs $cmd --name $csum --idtype uid \
--idmap $client_id:$fs_id; then
rc=$((rc + 1))
fi
if ! do_facet mgs $cmd --name $csum --idtype gid \
--idmap $client_id:$fs_id; then
rc=$((rc + 1))
fi
if $do_proj; then
if ! do_facet mgs $cmd --name $csum \
--idtype projid --idmap \
$client_id:$fs_id; then
rc=$((rc + 1))
fi
fi
done
done
return $rc
}
delete_root_idmaps() {
local i
local cmd="$LCTL $nodemap_del_idmap"
local rc=0
echo "Start to delete root idmaps ..."
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $cmd --name $csum --idtype uid \
--idmap 0:1; then
rc=$((rc + 1))
fi
if ! do_facet mgs $cmd --name $csum --idtype gid \
--idmap 0:1; then
rc=$((rc + 1))
fi
done
return $rc
}
modify_flags() {
local i
local proc
local option
local cmd="$LCTL $nodemap_modify"
local rc=0
proc[0]="admin_nodemap"
proc[1]="trusted_nodemap"
option[0]="admin"
option[1]="trusted"
for ((idx = 0; idx < 2; idx++)); do
if ! do_facet mgs $cmd --name $1 --property ${option[$idx]} \
--value 1; then
rc=$((rc + 1))
fi
if ! do_facet mgs $cmd --name $1 --property ${option[$idx]} \
--value 0; then
rc=$((rc + 1))
fi
done
return $rc
}
squash_id() {
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
local cmd
cmd[0]="$LCTL $nodemap_modify --property squash_uid"
cmd[1]="$LCTL $nodemap_modify --property squash_gid"
cmd[2]="$LCTL $nodemap_modify --property squash_projid"
if ! do_facet mgs ${cmd[$3]} --name $1 --value $2; then
return 1
fi
}
# ensure that the squash defaults are the expected defaults
squash_id default ${NOBODY_UID:-65534} 0
wait_nm_sync default squash_uid '' inactive
squash_id default ${NOBODY_UID:-65534} 1
wait_nm_sync default squash_gid '' inactive
if [ "$MDS1_VERSION" -ge $(version_code 2.14.50) ]; then
squash_id default ${NOBODY_UID:-65534} 2
wait_nm_sync default squash_projid '' inactive
fi
test_nid() {
local cmd
cmd="$LCTL $nodemap_test_nid"
nid=$(do_facet mgs $cmd $1)
if [ $nid == $2 ]; then
return 0
fi
return 1
}
cleanup_active() {
# restore activation state
do_facet mgs $LCTL $nodemap_activate 0
wait_nm_sync active
}
test_idmap() {
local i
local cmd="$LCTL $nodemap_test_id"
local do_root_idmap=true
local rc=0
(( $MDS1_VERSION >= $(version_code 2.15.60) )) || do_root_idmap=false
echo "Start to test idmaps ..."
## nodemap deactivated
if ! do_facet mgs $LCTL $nodemap_activate 0; then
return 1
fi
for ((id = $ID0; id < NODEMAP_MAX_ID; id++)); do
local j
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
local nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
local fs_id=$(do_facet mgs $cmd --nid $nid \
--idtype uid --id $id)
if [ $fs_id != $id ]; then
echo "expected $id, got $fs_id"
rc=$((rc + 1))
fi
done
done
## nodemap activated
if ! do_facet mgs $LCTL $nodemap_activate 1; then
return 2
fi
for ((id = $ID0; id < NODEMAP_MAX_ID; id++)); do
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid \
--idtype uid --id $id)
expected_id=$((id + 1))
if [ $fs_id != $expected_id ]; then
echo "expected $expected_id, got $fs_id"
rc=$((rc + 1))
fi
done
done
## trust client ids
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $LCTL $nodemap_modify --name $csum \
--property trusted --value 1; then
error "$nodemap_modify $csum failed with $?"
return 3
fi
done
for ((id = $ID0; id < NODEMAP_MAX_ID; id++)); do
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid \
--idtype uid --id $id)
if [ $fs_id != $id ]; then
echo "expected $id, got $fs_id"
rc=$((rc + 1))
fi
done
done
## ensure allow_root_access is enabled
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $LCTL $nodemap_modify --name $csum \
--property admin --value 1; then
error "$nodemap_modify $csum failed with $?"
return 3
fi
done
## check that root allowed
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid --idtype uid --id 0)
if [ $fs_id != 0 ]; then
echo "root allowed expected 0, got $fs_id"
rc=$((rc + 1))
fi
done
if $do_root_idmap; then
## add mapping for root
add_root_idmaps
## check that root allowed
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid \
--idtype uid --id 0)
if [ $fs_id != 0 ]; then
echo "root allowed expected 0, got $fs_id"
rc=$((rc + 1))
fi
done
## delete mapping for root
delete_root_idmaps
fi
## ensure allow_root_access is disabled
for ((i = 0; i < NODEMAP_COUNT; i++)); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $LCTL $nodemap_modify --name $csum \
--property admin --value 0; then
error "$nodemap_modify ${HOSTNAME_CHECKSUM}_${i} "
"failed with $rc"
return 3
fi
done
## check that root is mapped to NOBODY_UID
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid --idtype uid --id 0)
if [ $fs_id != ${NOBODY_UID:-65534} ]; then
error "root squash expect ${NOBODY_UID:-65534} got $fs_id"
rc=$((rc + 1))
fi
done
if $do_root_idmap; then
## add mapping for root
add_root_idmaps
## check root is mapped
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
nid="$SUBNET_CHECKSUM.0.${j}.100@tcp"
fs_id=$(do_facet mgs $cmd --nid $nid \
--idtype uid --id 0)
expected_id=1
if [ $fs_id != $expected_id ]; then
echo "expected $expected_id, got $fs_id"
rc=$((rc + 1))
fi
done
## delete mapping for root
delete_root_idmaps
fi
## reset client trust to 0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! do_facet mgs $LCTL $nodemap_modify \
--name ${HOSTNAME_CHECKSUM}_${i} \
--property trusted --value 0; then
error "$nodemap_modify ${HOSTNAME_CHECKSUM}_${i} "
"failed with $rc"
return 3
fi
done
return $rc
}
test_7() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc"
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc"
return 0
}
run_test 7 "nodemap create and delete"
test_8() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
# Set up nodemaps
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
# Try duplicates
create_nodemaps
rc=$?
[[ $rc == 0 ]] && error "duplicate nodemap_add allowed with $rc" &&
return 2
# Clean up
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 3
return 0
}
run_test 8 "nodemap reject duplicates"
test_9() {
local i
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! add_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_add_range failed with $rc" && return 2
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! delete_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_del_range failed with $rc" && return 4
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 4
return 0
}
run_test 9 "nodemap range add"
test_10a() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! add_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_add_range failed with $rc" && return 2
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! add_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc == 0 ]] && error "nodemap_add_range duplicate add with $rc" &&
return 2
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! delete_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_del_range failed with $rc" && return 4
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 5
return 0
}
run_test 10a "nodemap reject duplicate ranges"
test_10b() {
[ "$MGS_VERSION" -lt $(version_code 2.10.53) ] &&
skip "Need MGS >= 2.10.53"
local nm1="nodemap1"
local nm2="nodemap2"
local nids="192.168.19.[0-255]@o2ib20"
do_facet mgs $LCTL nodemap_del $nm1 2>/dev/null
do_facet mgs $LCTL nodemap_del $nm2 2>/dev/null
do_facet mgs $LCTL nodemap_add $nm1 || error "Add $nm1 failed"
do_facet mgs $LCTL nodemap_add $nm2 || error "Add $nm2 failed"
do_facet mgs $LCTL nodemap_add_range --name $nm1 --range $nids ||
error "Add range $nids to $nm1 failed"
[ -n "$(do_facet mgs $LCTL get_param nodemap.$nm1.* |
grep start_nid)" ] || error "No range was found"
do_facet mgs $LCTL nodemap_del_range --name $nm2 --range $nids &&
error "Deleting range $nids from $nm2 should fail"
[ -n "$(do_facet mgs $LCTL get_param nodemap.$nm1.* |
grep start_nid)" ] || error "Range $nids should be there"
do_facet mgs $LCTL nodemap_del $nm1 || error "Delete $nm1 failed"
do_facet mgs $LCTL nodemap_del $nm2 || error "Delete $nm2 failed"
return 0
}
run_test 10b "delete range from the correct nodemap"
test_10c() { #LU-8912
[ "$MGS_VERSION" -lt $(version_code 2.10.57) ] &&
skip "Need MGS >= 2.10.57"
local nm="nodemap_lu8912"
local nid_range="10.210.[32-47].[0-255]@o2ib3"
local start_nid="10.210.32.0@o2ib3"
local end_nid="10.210.47.255@o2ib3"
local start_nid_found
local end_nid_found
do_facet mgs $LCTL nodemap_del $nm 2>/dev/null
do_facet mgs $LCTL nodemap_add $nm || error "Add $nm failed"
do_facet mgs $LCTL nodemap_add_range --name $nm --range $nid_range ||
error "Add range $nid_range to $nm failed"
start_nid_found=$(do_facet mgs $LCTL get_param nodemap.$nm.* |
awk -F '[,: ]' /start_nid/'{ print $9 }')
[ "$start_nid" == "$start_nid_found" ] ||
error "start_nid: $start_nid_found != $start_nid"
end_nid_found=$(do_facet mgs $LCTL get_param nodemap.$nm.* |
awk -F '[,: ]' /end_nid/'{ print $13 }')
[ "$end_nid" == "$end_nid_found" ] ||
error "end_nid: $end_nid_found != $end_nid"
do_facet mgs $LCTL nodemap_del $nm || error "Delete $nm failed"
return 0
}
run_test 10c "verfify contiguous range support"
test_10d() { #LU-8913
[ "$MGS_VERSION" -lt $(version_code 2.10.59) ] &&
skip "Need MGS >= 2.10.59"
local nm="nodemap_lu8913"
local nid_range="*@o2ib3"
local start_nid="0.0.0.0@o2ib3"
local end_nid="255.255.255.255@o2ib3"
local start_nid_found
local end_nid_found
do_facet mgs $LCTL nodemap_del $nm 2>/dev/null
do_facet mgs $LCTL nodemap_add $nm || error "Add $nm failed"
do_facet mgs $LCTL nodemap_add_range --name $nm --range $nid_range ||
error "Add range $nid_range to $nm failed"
start_nid_found=$(do_facet mgs $LCTL get_param nodemap.$nm.* |
awk -F '[,: ]' /start_nid/'{ print $9 }')
[ "$start_nid" == "$start_nid_found" ] ||
error "start_nid: $start_nid_found != $start_nid"
end_nid_found=$(do_facet mgs $LCTL get_param nodemap.$nm.* |
awk -F '[,: ]' /end_nid/'{ print $13 }')
[ "$end_nid" == "$end_nid_found" ] ||
error "end_nid: $end_nid_found != $end_nid"
do_facet mgs $LCTL nodemap_del $nm || error "Delete $nm failed"
return 0
}
run_test 10d "verfify nodemap range format '*@<net>' support"
test_11() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! modify_flags ${HOSTNAME_CHECKSUM}_${i}; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_modify with $rc" && return 2
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 3
return 0
}
run_test 11 "nodemap modify"
test_12() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! squash_id ${HOSTNAME_CHECKSUM}_${i} 88 0; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap squash_uid with $rc" && return 2
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! squash_id ${HOSTNAME_CHECKSUM}_${i} 88 1; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap squash_gid with $rc" && return 3
rc=0
if (( $MDS1_VERSION >= $(version_code 2.14.52) )); then
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! squash_id ${HOSTNAME_CHECKSUM}_${i} 88 2; then
rc=$((rc + 1))
fi
done
fi
[[ $rc != 0 ]] && error "nodemap squash_projid with $rc" && return 5
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 4
return 0
}
run_test 12 "nodemap set squash ids"
test_13() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! add_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_add_range failed with $rc" && return 2
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
for k in $NODEMAP_IPADDR_LIST; do
if ! test_nid $SUBNET_CHECKSUM.$i.$j.$k \
${HOSTNAME_CHECKSUM}_${i}; then
rc=$((rc + 1))
fi
done
done
done
[[ $rc != 0 ]] && error "nodemap_test_nid failed with $rc" && return 3
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 4
return 0
}
run_test 13 "test nids"
test_14() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
for ((j = 0; j < NODEMAP_RANGE_COUNT; j++)); do
for k in $NODEMAP_IPADDR_LIST; do
if ! test_nid $SUBNET_CHECKSUM.$i.$j.$k \
default; then
rc=$((rc + 1))
fi
done
done
done
[[ $rc != 0 ]] && error "nodemap_test_nid failed with $rc" && return 3
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del failed with $rc" && return 4
return 0
}
run_test 14 "test default nodemap nid lookup"
test_15() {
local rc
remote_mgs_nodsh && skip "remote MGS with nodsh"
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53"
rc=0
create_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add failed with $rc" && return 1
for (( i = 0; i < NODEMAP_COUNT; i++ )); do
local csum=${HOSTNAME_CHECKSUM}_${i}
if ! do_facet mgs $LCTL nodemap_modify --name $csum \
--property admin --value 0; then
rc=$((rc + 1))
fi
if ! do_facet mgs $LCTL nodemap_modify --name $csum \
--property trusted --value 0; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_modify failed with $rc" && return 1
rc=0
for ((i = 0; i < NODEMAP_COUNT; i++)); do
if ! add_range ${HOSTNAME_CHECKSUM}_${i} $i; then
rc=$((rc + 1))
fi
done
[[ $rc != 0 ]] && error "nodemap_add_range failed with $rc" && return 2
rc=0
add_idmaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_add_idmap failed with $rc" && return 3
activedefault=$(do_facet mgs $LCTL get_param -n nodemap.active)
if [[ "$activedefault" != "1" ]]; then
stack_trap cleanup_active EXIT
fi
rc=0
test_idmap
rc=$?
[[ $rc != 0 ]] && error "nodemap_test_id failed with $rc" && return 4
rc=0
update_idmaps
rc=$?
[[ $rc != 0 ]] && error "update_idmaps failed with $rc" && return 5
rc=0
delete_idmaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_del_idmap failed with $rc" && return 6
rc=0
delete_nodemaps
rc=$?
[[ $rc != 0 ]] && error "nodemap_delete failed with $rc" && return 7
return 0
}
run_test 15 "test id mapping"
create_fops_nodemaps() {
local i=0
local client
for client in $clients; do
local client_ip=$(host_nids_address $client $NETTYPE)
local client_nid=$(h2nettype $client_ip)
do_facet mgs $LCTL nodemap_add c${i} || return 1
do_facet mgs $LCTL nodemap_add_range \
--name c${i} --range $client_nid || {
do_facet mgs $LCTL nodemap_del c${i}
return 1
}
for map in ${FOPS_IDMAPS[i]}; do
do_facet mgs $LCTL nodemap_add_idmap --name c${i} \
--idtype uid --idmap ${map} || return 1
do_facet mgs $LCTL nodemap_add_idmap --name c${i} \
--idtype gid --idmap ${map} || return 1
done
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
# Load per-NM keys on servers
do_nodes $(comma_list $(all_server_nodes)) \
"$LGSS_SK -t server -l $SK_PATH/nodemap/c$i.key"
# Load per-NM keys on corresponding clients
do_node $client \
"$LGSS_SK -t client -l $SK_PATH/nodemap/c$i.key"
# flush gss context to force client to re-authenticate
# with per-NM key
do_node $client "$LFS flushctx $MOUNT || true"
if [ "$MOUNT_2" ]; then
do_node $client "$LFS flushctx $MOUNT2 || true"
fi
fi
i=$((i + 1))
done
wait_nm_sync c$((i - 1)) idmap
return 0
}
delete_fops_nodemaps() {
local i=0
local client
for client in $clients; do
do_facet mgs $LCTL nodemap_del c${i} || return 1
i=$((i + 1))
done
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
do_nodes $(comma_list $clients) \
"$LGSS_SK -t client -l $SK_PATH/$FSNAME.key"
# flush gss context to force client to re-authenticate
do_nodes $(comma_list $clients) "$LFS flushctx $MOUNT || true"
if [ "$MOUNT_2" ]; then
do_nodes $(comma_list $clients) \
"$LFS flushctx $MOUNT2 || true"
fi
fi
return 0
}
fops_mds_index=0
nm_test_mkdir() {
if [ $MDSCOUNT -le 1 ]; then
do_node ${clients_arr[0]} mkdir -p $DIR/$tdir
else
# round-robin MDTs to test DNE nodemap support
[ ! -d $DIR ] && do_node ${clients_arr[0]} mkdir -p $DIR
do_node ${clients_arr[0]} $LFS setdirstripe -c 1 -i \
$((fops_mds_index % MDSCOUNT)) $DIR/$tdir
((fops_mds_index++))
fi
}
# acl test directory needs to be initialized on a privileged client
fops_test_setup() {
local admin=$(do_facet mgs $LCTL get_param -n nodemap.c0.admin_nodemap)
local trust=$(do_facet mgs $LCTL get_param -n \
nodemap.c0.trusted_nodemap)
do_facet mgs $LCTL nodemap_modify --name c0 --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted --value 1
wait_nm_sync c0 trusted_nodemap
do_nodes $(comma_list $clients) $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear
do_node ${clients_arr[0]} rm -rf $DIR/$tdir
nm_test_mkdir
do_node ${clients_arr[0]} chown $user $DIR/$tdir
do_facet mgs $LCTL nodemap_modify --name c0 \
--property admin --value $admin
do_facet mgs $LCTL nodemap_modify --name c0 \
--property trusted --value $trust
wait_nm_sync c0 trusted_nodemap
# flush MDT locks to make sure they are reacquired before test
do_nodes $(comma_list $clients) $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear
}
# fileset test directory needs to be initialized on a privileged client
fileset_test_setup() {
local nm=$1
local modify_val=""
# exercise new nodemap_modify syntax if available
(( $MGS_VERSION >= $(version_code 2.16.51) )) ||
modify_val=" --value"
if [[ -n $FILESET && -z $SKIP_FILESET ]]; then
cleanup_mount $MOUNT
FILESET="" zconf_mount_clients $CLIENTS $MOUNT
fi
local admin=$(do_facet mgs $LCTL get_param -n \
nodemap.${nm}.admin_nodemap)
local trust=$(do_facet mgs $LCTL get_param -n \
nodemap.${nm}.trusted_nodemap)
do_facet mgs $LCTL nodemap_modify --name $nm \
--property admin${modify_val}=1
do_facet mgs $LCTL nodemap_modify --name $nm \
--property trusted${modify_val}=1
wait_nm_sync $nm trusted_nodemap
# create directory and populate it for subdir mount
do_node ${clients_arr[0]} mkdir $MOUNT/$subdir ||
error "unable to create dir $MOUNT/$subdir"
do_node ${clients_arr[0]} touch $MOUNT/$subdir/this_is_$subdir ||
error "unable to create file $MOUNT/$subdir/this_is_$subdir"
do_node ${clients_arr[0]} mkdir $MOUNT/$subdir/$subsubdir ||
error "unable to create dir $MOUNT/$subdir/$subsubdir"
do_node ${clients_arr[0]} touch \
$MOUNT/$subdir/$subsubdir/this_is_$subsubdir ||
error "unable to create file \
$MOUNT/$subdir/$subsubdir/this_is_$subsubdir"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property admin${modify_val}=$admin
do_facet mgs $LCTL nodemap_modify --name $nm \
--property trusted${modify_val}=$trust
# flush MDT locks to make sure they are reacquired before test
do_node ${clients_arr[0]} $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear
wait_nm_sync $nm trusted_nodemap
}
# fileset test directory needs to be initialized on a privileged client
fileset_test_cleanup() {
local nm=$1
local admin=$(do_facet mgs $LCTL get_param -n \
nodemap.${nm}.admin_nodemap)
local trust=$(do_facet mgs $LCTL get_param -n \
nodemap.${nm}.trusted_nodemap)
do_facet mgs $LCTL nodemap_modify --name $nm --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name $nm --property trusted \
--value 1
wait_nm_sync $nm trusted_nodemap
# cleanup directory created for subdir mount
do_node ${clients_arr[0]} rm -rf $MOUNT/$subdir ||
error "unable to remove dir $MOUNT/$subdir"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property admin --value $admin
do_facet mgs $LCTL nodemap_modify --name $nm \
--property trusted --value $trust
# flush MDT locks to make sure they are reacquired before test
do_node ${clients_arr[0]} $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear || true
wait_nm_sync $nm trusted_nodemap
if [ -n "$FILESET" -a -z "$SKIP_FILESET" ]; then
cleanup_mount $MOUNT
zconf_mount_clients $CLIENTS $MOUNT
fi
}
do_create_delete() {
local run_u=$1
local key=$2
local testfile=$DIR/$tdir/$tfile
local rc=0
local c=0 d=0
local qused_new
if $run_u touch $testfile >& /dev/null; then
c=1
$run_u rm $testfile && d=1
fi >& /dev/null
local res="$c $d"
local expected=$(get_cr_del_expected $key)
[ "$res" != "$expected" ] &&
error "test $key, wanted $expected, got $res" && rc=$((rc + 1))
return $rc
}
nodemap_check_quota() {
local run_u="$1"
$run_u lfs quota -q $DIR | awk '{ print $2; exit; }'
}
do_fops_quota_test() {
local run_u=$1
# fuzz quota used to account for possible indirect blocks, etc
local quota_fuzz=$(fs_log_size)
local qused_orig=$(nodemap_check_quota "$run_u")
local qused_high=$((qused_orig + quota_fuzz))
local qused_low=$((qused_orig - quota_fuzz))
local testfile=$DIR/$tdir/$tfile
$run_u dd if=/dev/zero of=$testfile oflag=sync bs=1M count=1 \
>& /dev/null || error "unable to write quota test file"
sync; sync_all_data || true
local qused_new=$(nodemap_check_quota "$run_u")
[ $((qused_new)) -lt $((qused_low + 1024)) -o \
$((qused_new)) -gt $((qused_high + 1024)) ] &&
error "$qused_new != $qused_orig + 1M after write, " \
"fuzz is $quota_fuzz"
$run_u rm $testfile || error "unable to remove quota test file"
wait_delete_completed_mds
qused_new=$(nodemap_check_quota "$run_u")
[ $((qused_new)) -lt $((qused_low)) \
-o $((qused_new)) -gt $((qused_high)) ] &&
error "quota not reclaimed, expect $qused_orig, " \
"got $qused_new, fuzz $quota_fuzz"
}
get_fops_mapped_user() {
local cli_user=$1
for ((i=0; i < ${#FOPS_IDMAPS[@]}; i++)); do
for map in ${FOPS_IDMAPS[i]}; do
if [ $(cut -d: -f1 <<< "$map") == $cli_user ]; then
cut -d: -f2 <<< "$map"
return
fi
done
done
echo -1
}
get_cr_del_expected() {
local -a key
IFS=":" read -a key <<< "$1"
local mapmode="${key[0]}"
local mds_user="${key[1]}"
local cluster="${key[2]}"
local cli_user="${key[3]}"
local mode="0${key[4]}"
local SUCCESS="1 1"
local FAILURE="0 0"
local noadmin=0
local mapped=0
local other=0
[[ $mapmode == *mapped* ]] && mapped=1
# only c1 is mapped in these test cases
[[ $mapmode == mapped_trusted* ]] && [ "$cluster" == "c0" ] && mapped=0
[[ $mapmode == *noadmin* ]] && noadmin=1
# o+wx works as long as the user isn't mapped
if [ $((mode & 3)) -eq 3 ]; then
other=1
fi
# if client user is root, check if root is squashed
if [ "$cli_user" == "0" ]; then
# squash root succeed, if other bit is on
case $noadmin in
0) echo $SUCCESS;;
1) [ "$other" == "1" ] && echo $SUCCESS
[ "$other" == "0" ] && echo $FAILURE;;
esac
return
fi
if [ "$mapped" == "0" ]; then
[ "$other" == "1" ] && echo $SUCCESS
[ "$other" == "0" ] && echo $FAILURE
return
fi
# if mapped user is mds user, check for u+wx
mapped_user=$(get_fops_mapped_user $cli_user)
[ "$mapped_user" == "-1" ] &&
error "unable to find mapping for client user $cli_user"
if [ "$mapped_user" == "$mds_user" -a \
$(((mode & 0300) == 0300)) -eq 1 ]; then
echo $SUCCESS
return
fi
if [ "$mapped_user" != "$mds_user" -a "$other" == "1" ]; then
echo $SUCCESS
return
fi
echo $FAILURE
}
test_fops_admin_cli_i=""
test_fops_chmod_dir() {
local current_cli_i=$1
local perm_bits=$2
local dir_to_chmod=$3
local new_admin_cli_i=""
# do we need to set up a new admin client?
[ "$current_cli_i" == "0" ] && [ "$test_fops_admin_cli_i" != "1" ] &&
new_admin_cli_i=1
[ "$current_cli_i" != "0" ] && [ "$test_fops_admin_cli_i" != "0" ] &&
new_admin_cli_i=0
# if only one client, and non-admin, need to flip admin everytime
if [ "$num_clients" == "1" ]; then
test_fops_admin_client=$clients
test_fops_admin_val=$(do_facet mgs $LCTL get_param -n \
nodemap.c0.admin_nodemap)
if [ "$test_fops_admin_val" != "1" ]; then
do_facet mgs $LCTL nodemap_modify \
--name c0 \
--property admin \
--value 1
wait_nm_sync c0 admin_nodemap
fi
elif [ "$new_admin_cli_i" != "" ]; then
# restore admin val to old admin client
if [ "$test_fops_admin_cli_i" != "" ] &&
[ "$test_fops_admin_val" != "1" ]; then
do_facet mgs $LCTL nodemap_modify \
--name c${test_fops_admin_cli_i} \
--property admin \
--value $test_fops_admin_val
wait_nm_sync c${test_fops_admin_cli_i} admin_nodemap
fi
test_fops_admin_cli_i=$new_admin_cli_i
test_fops_admin_client=${clients_arr[$new_admin_cli_i]}
test_fops_admin_val=$(do_facet mgs $LCTL get_param -n \
nodemap.c${new_admin_cli_i}.admin_nodemap)
if [ "$test_fops_admin_val" != "1" ]; then
do_facet mgs $LCTL nodemap_modify \
--name c${new_admin_cli_i} \
--property admin \
--value 1
wait_nm_sync c${new_admin_cli_i} admin_nodemap
fi
fi
do_node $test_fops_admin_client chmod $perm_bits $DIR/$tdir || return 1
# remove admin for single client if originally non-admin
if [ "$num_clients" == "1" ] && [ "$test_fops_admin_val" != "1" ]; then
do_facet mgs $LCTL nodemap_modify --name c0 --property admin \
--value 0
wait_nm_sync c0 admin_nodemap
fi
return 0
}
test_fops() {
local mapmode="$1"
local single_client="$2"
local client_user_list=([0]="0 $((IDBASE+3))"
[1]="0 $((IDBASE+5))")
local mds_users="-1 0"
local mds_i
local rc=0
local perm_bit_list="3 $((0300))"
# SLOW tests 000-007, 010-070, 100-700 (octal modes)
if [ "$SLOW" == "yes" ]; then
perm_bit_list="0 $(seq 1 7) $(seq 8 8 63) $(seq 64 64 511) \
$((0303))"
client_user_list=([0]="0 $((IDBASE+3)) $((IDBASE+4))"
[1]="0 $((IDBASE+5)) $((IDBASE+6))")
mds_users="-1 0 1 2"
fi
# force single_client to speed up test
[ "$SLOW" == "yes" ] ||
single_client=1
# step through mds users. -1 means root
for mds_i in $mds_users; do
local user=$((mds_i + IDBASE))
local client
local x
[ "$mds_i" == "-1" ] && user=0
echo mkdir -p $DIR/$tdir
fops_test_setup
local cli_i=0
for client in $clients; do
local u
for u in ${client_user_list[$cli_i]}; do
local run_u="do_node $client \
$RUNAS_CMD -u$u -g$u -G$u"
for perm_bits in $perm_bit_list; do
local mode=$(printf %03o $perm_bits)
local key
key="$mapmode:$user:c$cli_i:$u:$mode"
test_fops_chmod_dir $cli_i $mode \
$DIR/$tdir ||
error cannot chmod $key
do_create_delete "$run_u" "$key"
done
# check quota
test_fops_chmod_dir $cli_i 777 $DIR/$tdir ||
error cannot chmod $key
do_fops_quota_test "$run_u"
done
cli_i=$((cli_i + 1))
[ "$single_client" == "1" ] && break
done
rm -rf $DIR/$tdir
done
return $rc
}
nodemap_version_check () {
remote_mgs_nodsh && skip "remote MGS with nodsh" && return 1
[ "$MGS_VERSION" -lt $(version_code 2.5.53) ] &&
skip "No nodemap on $MGS_VERSION MGS < 2.5.53" &&
return 1
return 0
}
nodemap_test_setup() {
local rc
local active_nodemap=1
[ "$1" == "0" ] && active_nodemap=0
do_nodes $(all_mdts_nodes) "$LCTL set_param mdt.*.identity_upcall=NONE"
rc=0
create_fops_nodemaps
rc=$?
[[ $rc != 0 ]] && error "adding fops nodemaps failed $rc"
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
wait_nm_sync default trusted_nodemap '' inactive
do_facet mgs $LCTL nodemap_activate $active_nodemap
wait_nm_sync active
wait_ssk
}
nodemap_test_cleanup() {
trap 0
delete_fops_nodemaps
rc=$?
[[ $rc != 0 ]] && error "removing fops nodemaps failed $rc"
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0
wait_nm_sync default trusted_nodemap
do_facet mgs $LCTL nodemap_activate 0
wait_nm_sync active 0
export SK_UNIQUE_NM=false
wait_ssk
return 0
}
nodemap_clients_admin_trusted() {
local admin=$1
local tr=$2
local i=0
for client in $clients; do
do_facet mgs $LCTL nodemap_modify --name c0 \
--property admin --value $admin
do_facet mgs $LCTL nodemap_modify --name c0 \
--property trusted --value $tr
i=$((i + 1))
done
wait_nm_sync c$((i - 1)) trusted_nodemap
}
test_16() {
nodemap_version_check || return 0
nodemap_test_setup 0
trap nodemap_test_cleanup EXIT
test_fops all_off
nodemap_test_cleanup
}
run_test 16 "test nodemap all_off fileops"
test_17() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
local check_proj=true
(( $MDS1_VERSION >= $(version_code 2.14.52) )) || check_proj=false
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
nodemap_clients_admin_trusted 0 1
test_fops trusted_noadmin 1
if $check_proj; then
do_facet mgs $LCTL nodemap_modify --name c0 \
--property map_mode --value projid
wait_nm_sync c0 map_mode
fi
test_fops trusted_noadmin 1
nodemap_test_cleanup
}
run_test 17 "test nodemap trusted_noadmin fileops"
test_18() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
nodemap_clients_admin_trusted 0 0
test_fops mapped_noadmin 1
nodemap_test_cleanup
}
run_test 18 "test nodemap mapped_noadmin fileops"
test_19() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
nodemap_clients_admin_trusted 1 1
test_fops trusted_admin 1
nodemap_test_cleanup
}
run_test 19 "test nodemap trusted_admin fileops"
test_20() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
nodemap_clients_admin_trusted 1 0
test_fops mapped_admin 1
nodemap_test_cleanup
}
run_test 20 "test nodemap mapped_admin fileops"
test_21() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
local x=1
local i=0
for client in $clients; do
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property admin --value 0
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property trusted --value $x
x=0
i=$((i + 1))
done
wait_nm_sync c$((i - 1)) trusted_nodemap
test_fops mapped_trusted_noadmin
nodemap_test_cleanup
}
run_test 21 "test nodemap mapped_trusted_noadmin fileops"
test_22() {
if $SHARED_KEY &&
[ "$MDS1_VERSION" -lt $(version_code 2.11.55) ]; then
skip "Need MDS >= 2.11.55"
fi
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
local x=1
local i=0
for client in $clients; do
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property trusted --value $x
x=0
i=$((i + 1))
done
wait_nm_sync c$((i - 1)) trusted_nodemap
test_fops mapped_trusted_admin
nodemap_test_cleanup
}
run_test 22 "test nodemap mapped_trusted_admin fileops"
# acl test directory needs to be initialized on a privileged client
nodemap_acl_test_setup() {
local admin=$(do_facet mgs $LCTL get_param -n \
nodemap.c0.admin_nodemap)
local trust=$(do_facet mgs $LCTL get_param -n \
nodemap.c0.trusted_nodemap)
do_facet mgs $LCTL nodemap_modify --name c0 --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted --value 1
wait_nm_sync c0 trusted_nodemap
do_node ${clients_arr[0]} rm -rf $DIR/$tdir
nm_test_mkdir
do_node ${clients_arr[0]} chmod a+rwx $DIR/$tdir ||
error unable to chmod a+rwx test dir $DIR/$tdir
do_facet mgs $LCTL nodemap_modify --name c0 \
--property admin --value $admin
do_facet mgs $LCTL nodemap_modify --name c0 \
--property trusted --value $trust
wait_nm_sync c0 trusted_nodemap
}
# returns 0 if the number of ACLs does not change on the second (mapped) client
# after being set on the first client
nodemap_acl_test() {
local user="$1"
local set_client="$2"
local get_client="$3"
local check_setfacl="$4"
local setfacl_error=0
local testfile=$DIR/$tdir/$tfile
local RUNAS_USER="$RUNAS_CMD -u $user"
local acl_count=0
local acl_count_post=0
nodemap_acl_test_setup
sleep 5
do_node $set_client $RUNAS_USER touch $testfile
# remove from cache, otherwise ACLs will not be fetched from server
do_rpc_nodes $set_client cancel_lru_locks
do_node $set_client "sync ; echo 3 > /proc/sys/vm/drop_caches"
# ACL masks aren't filtered by nodemap code, so we ignore them
acl_count=$(do_node $get_client getfacl $testfile | grep -v mask |
wc -l)
# remove from cache, otherwise ACLs will not be fetched from server
do_rpc_nodes $get_client cancel_lru_locks
do_node $get_client "sync ; echo 3 > /proc/sys/vm/drop_caches"
do_node $set_client $RUNAS_USER setfacl -m $user:rwx $testfile ||
setfacl_error=1
# remove from cache, otherwise ACLs will not be fetched from server
do_rpc_nodes $set_client cancel_lru_locks
do_node $set_client "sync ; echo 3 > /proc/sys/vm/drop_caches"
# if check setfacl is set to 1, then it's supposed to error
if [ "$check_setfacl" == "1" ]; then
[ "$setfacl_error" != "1" ] && return 1
return 0
fi
[ "$setfacl_error" == "1" ] && echo "WARNING: unable to setfacl"
acl_count_post=$(do_node $get_client getfacl $testfile | grep -v mask |
wc -l)
# remove from cache, otherwise ACLs will not be fetched from server
do_rpc_nodes $get_client cancel_lru_locks
do_node $get_client "sync ; echo 3 > /proc/sys/vm/drop_caches"
[ $acl_count -eq $acl_count_post ] && return 0
return 1
}
test_23a() {
[ $num_clients -lt 2 ] && skip "Need 2 clients at least" && return
nodemap_version_check || return 0
nodemap_test_setup
trap nodemap_test_cleanup EXIT
# 1 trusted cluster, 1 mapped cluster
local unmapped_fs=$((IDBASE+0))
local unmapped_c1=$((IDBASE+5))
local mapped_fs=$((IDBASE+2))
local mapped_c0=$((IDBASE+4))
local mapped_c1=$((IDBASE+6))
do_facet mgs $LCTL nodemap_modify --name c0 --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted --value 1
do_facet mgs $LCTL nodemap_modify --name c1 --property admin --value 0
do_facet mgs $LCTL nodemap_modify --name c1 --property trusted --value 0
wait_nm_sync c1 trusted_nodemap
# setfacl on trusted cluster to unmapped user, verify it's not seen
nodemap_acl_test $unmapped_fs ${clients_arr[0]} ${clients_arr[1]} ||
error "acl count (1)"
# setfacl on trusted cluster to mapped user, verify it's seen
nodemap_acl_test $mapped_fs ${clients_arr[0]} ${clients_arr[1]} &&
error "acl count (2)"
# setfacl on mapped cluster to mapped user, verify it's seen
nodemap_acl_test $mapped_c1 ${clients_arr[1]} ${clients_arr[0]} &&
error "acl count (3)"
# setfacl on mapped cluster to unmapped user, verify error
nodemap_acl_test $unmapped_fs ${clients_arr[1]} ${clients_arr[0]} 1 ||
error "acl count (4)"
# 2 mapped clusters
do_facet mgs $LCTL nodemap_modify --name c0 --property admin --value 0
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted --value 0
wait_nm_sync c0 trusted_nodemap
# setfacl to mapped user on c1, also mapped to c0, verify it's seen
nodemap_acl_test $mapped_c1 ${clients_arr[1]} ${clients_arr[0]} &&
error "acl count (5)"
# setfacl to mapped user on c1, not mapped to c0, verify not seen
nodemap_acl_test $unmapped_c1 ${clients_arr[1]} ${clients_arr[0]} ||
error "acl count (6)"
nodemap_test_cleanup
}
run_test 23a "test mapped regular ACLs"
test_23b() { #LU-9929
(( num_clients >= 2 )) || skip "Need 2 clients at least"
(( $MGS_VERSION >= $(version_code 2.10.53) )) ||
skip "Need MGS >= 2.10.53"
stack_trap "export SK_UNIQUE_NM=$SK_UNIQUE_NM"
export SK_UNIQUE_NM=true
nodemap_test_setup
stack_trap nodemap_test_cleanup EXIT
local testdir=$DIR/$tdir
local fs_id=$((IDBASE+10))
local unmapped_id
local mapped_id
local fs_user
do_facet mgs $LCTL nodemap_modify --name c0 --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c1 --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c1 --property trusted --value 1
# Add idmap $ID0:$fs_id (500:60010)
do_facet mgs $LCTL nodemap_add_idmap --name c0 --idtype gid \
--idmap $ID0:$fs_id ||
error "add idmap $ID0:$fs_id to nodemap c0 failed"
wait_nm_sync c0 idmap
# set/getfacl default acl on client 1 (unmapped gid=500)
do_node ${clients_arr[0]} rm -rf $testdir
do_node ${clients_arr[0]} mkdir -p $testdir
echo "$testdir ACLs after mkdir:"
do_node ${clients_arr[0]} getfacl $testdir
# Here, USER0=$(getent passwd | grep :$ID0:$ID0: | cut -d: -f1)
do_node ${clients_arr[0]} setfacl -R -d -m group:$USER0:rwx $testdir ||
error "setfacl $testdir on ${clients_arr[0]} failed"
do_node ${clients_arr[0]} "sync && stat $testdir > /dev/null"
do_node ${clients_arr[0]} \
$LCTL set_param -t4 -n "ldlm.namespaces.*.lru_size=clear"
echo "$testdir ACLs after setfacl, on ${clients_arr[0]}:"
do_node ${clients_arr[0]} getfacl $testdir
unmapped_id=$(do_node ${clients_arr[0]} getfacl $testdir |
grep -E "default:group:.+:rwx" | awk -F: '{print $3}')
echo unmapped_id=$unmapped_id
(( unmapped_id == USER0 )) ||
error "gid=$ID0 was not unmapped correctly on ${clients_arr[0]}"
# getfacl default acl on client 2 (mapped gid=60010)
do_node ${clients_arr[1]} \
$LCTL set_param -t4 -n "ldlm.namespaces.*.lru_size=clear"
do_node ${clients_arr[1]} "sync && stat $testdir > /dev/null"
echo "$testdir ACLs after setfacl, on ${clients_arr[1]}:"
do_node ${clients_arr[1]} getfacl $testdir
mapped_id=$(do_node ${clients_arr[1]} getfacl $testdir |
grep -E "default:group:.+:rwx" | awk -F: '{print $3}')
echo mapped_id=$mapped_id
[[ -n "$mapped_id" ]] || error "mapped_id empty"
fs_user=$(do_node ${clients_arr[1]} getent passwd |
grep :$fs_id:$fs_id: | cut -d: -f1)
[[ -n "$fs_user" ]] || fs_user=$fs_id
echo fs_user=$fs_user
(( mapped_id == fs_id || mapped_id == fs_user )) ||
error "Should return user $fs_user id $fs_id on client2"
}
run_test 23b "test mapped default ACLs"
test_24() {
nodemap_test_setup
trap nodemap_test_cleanup EXIT
do_nodes $(all_server_nodes) $LCTL get_param -R nodemap
nodemap_test_cleanup
}
run_test 24 "check nodemap proc files for LBUGs and Oopses"
function filter_nodemap_info() {
local awkcmd
local facet=$1
shift
awkcmd='/^nodemap[.].*[.]dt_stats[:=]/{ignore=1; next}
/^nodemap[.].*[.]md_stats[:=]/{ignore=1; next}
/^nodemap./{ignore=0}
{if(ignore==0)print}'
do_facet $facet $LCTL $* | awk "$awkcmd"
return ${PIPESTATUS[0]}
}
test_25a() {
local tmpfile=$(mktemp)
local tmpfile2=$(mktemp)
local tmpfile3=$(mktemp)
local tmpfile4=$(mktemp)
local subdir=c0dir
local client
stack_trap "rm -f $tmpfile $tmpfile2 $tmpfile3 $tmpfile4"
nodemap_version_check || return 0
# in local mode the exports order on the nodemap cannot be compared
local_mode && skip "test does not support local mode"
# stop clients for this test
zconf_umount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
export SK_UNIQUE_NM=true
nodemap_test_setup
# enable trusted/admin for setquota call in cleanup_and_setup_lustre()
i=0
for client in $clients; do
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property trusted --value 1
((i++))
done
wait_nm_sync c$((i - 1)) trusted_nodemap
trap nodemap_test_cleanup EXIT
# create a new, empty nodemap, and add fileset info to it
do_facet mgs $LCTL nodemap_add test25 ||
error "unable to create nodemap $testname"
do_facet mgs $LCTL set_param -P nodemap.$testname.fileset=/$subdir ||
error "unable to add fileset info to nodemap test25"
wait_nm_sync test25 id
filter_nodemap_info mgs $nodemap_info >$tmpfile
filter_nodemap_info mds $nodemap_info >$tmpfile2
if ! $SHARED_KEY; then
# will conflict with SK's nodemaps
cleanup_and_setup_lustre
fi
# stop clients for this test
zconf_umount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
filter_nodemap_info mgs $nodemap_info >$tmpfile3
diff -q $tmpfile3 $tmpfile >& /dev/null || {
echo "== $tmpfile =="
cat $tmpfile
echo "== $tmpfile3 =="
cat $tmpfile3
echo
error "$nodemap_info diff on MGS after remount"
}
filter_nodemap_info mds $nodemap_info >$tmpfile4
diff -q $tmpfile4 $tmpfile2 >& /dev/null || {
echo "== $tmpfile4 =="
cat $tmpfile4
echo "== $tmpfile2 =="
cat $tmpfile2
echo
error "$nodemap_info diff on MDS after remount"
}
# cleanup nodemap
do_facet mgs $LCTL nodemap_del test25 ||
error "cannot delete nodemap test25 from config"
nodemap_test_cleanup
# restart clients previously stopped
zconf_mount_clients $CLIENTS $MOUNT ||
error "unable to mount clients $CLIENTS"
export SK_UNIQUE_NM=false
}
run_test 25a "test save and reload nodemap config"
test_25b() {
local nm="c0"
local info_dump=$(mktemp)
local param_dump=$(mktemp)
(( $MGS_VERSION >= $(version_code 2.16.52) )) ||
skip "Need MGS >= 2.16.52 for updated nodemap_info"
# in local mode the exports order on the nodemap cannot be compared
local_mode && skip "test does not support local mode"
nodemap_test_setup
stack_trap nodemap_test_cleanup EXIT
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
fi
# fill some more values on nodemap
# We test only local here, so no wait_nm_sync required
do_facet mgs $LCTL nodemap_add_offset --name $nm \
--offset 1000000 --limit 100000 ||
error "cannot set offset $nm"
do_facet mgs $LCTL nodemap_set_fileset --name $nm \
--fileset "/somedir" ||
error "unable to add fileset info"
# full nodemap dump
filter_nodemap_info mgs $nodemap_info > $info_dump ||
error "$nodemap_info failed"
stack_trap "rm -f $info_dump" EXIT
filter_nodemap_info mgs get_param -R nodemap > $param_dump ||
error "get_param -R nodemap failed"
stack_trap "rm -f $param_dump" EXIT
diff -q $info_dump $param_dump >& /dev/null ||
error "$nodemap_info differs from get_param output (1)"
# nodemap dump for $nm
filter_nodemap_info mgs $nodemap_info --name $nm > $info_dump ||
error "$nodemap_info failed"
filter_nodemap_info mgs get_param -R nodemap.$nm > $param_dump ||
error "get_param -R nodemap.$nm failed"
diff -q $info_dump $param_dump >& /dev/null ||
error "$nodemap_info differs from get_param output (2)"
# nodemap dump for $nm and property fileset
filter_nodemap_info mgs $nodemap_info --name $nm \
--property fileset > $info_dump ||
error "$nodemap_info failed"
filter_nodemap_info mgs get_param nodemap.$nm.fileset > $param_dump ||
error "get_param nodemap.$nm.fileset failed"
diff -q $info_dump $param_dump >& /dev/null ||
error "$nodemap_info differs from get_param output (3)"
# cross nodemap dump for property ranges
do_facet mgs $LCTL $nodemap_info --property ranges > $info_dump ||
error "$nodemap_info failed"
do_facet mgs $LCTL get_param -R nodemap.*.ranges > $param_dump ||
error "get_param -R nodemap.*.ranges failed"
diff -q $info_dump $param_dump >& /dev/null ||
error "$nodemap_info differs from get_param output (4)"
# back to non-nodemap setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
fi
}
run_test 25b "test nodemap info values"
cleanup_25c() {
# back to non-nodemap setup
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
fi
# cleanup deletes set traps
nodemap_test_cleanup
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to remount client ${clients_arr[0]}"
wait_ssk
}
test_25c() {
local nm="c0"
local fileset="/$tdir"
verify_yaml_available || skip_env "YAML verification not installed"
(( $MGS_VERSION >= $(version_code 2.16.59) )) ||
skip "Need MGS >= 2.16.59 for get_param yaml output"
$LFS mkdir -c 1 "${DIR}${fileset}" ||
error "failed to mkdir ${DIR}${fileset}"
nodemap_test_setup
stack_trap cleanup_25c
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
fi
# fill some more values on nodemap
do_facet mgs $LCTL nodemap_fileset_add --name $nm --fileset $fileset ||
error "unable to add fileset"
do_facet mgs $LCTL nodemap_add_offset --name $nm \
--offset 1000000 --limit 100000 || error "cannot set offset $nm"
wait_nm_sync $nm offset
# remount client to populate nodemap exports
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
FILESET="/" \
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to remount client ${clients_arr[0]}"
wait_ssk
# Ignore per-nodemap stats when checking for YAML-compliance
echo "Filtered nodemap output:"
filter_nodemap_info mds1 get_param -R -y nodemap
filter_nodemap_info mds1 get_param -R -y nodemap | verify_yaml ||
error "nodemap yaml could not be verified"
}
run_test 25c "test yaml-compliance for nodemap"
test_26() {
nodemap_version_check || return 0
local large_i=32000
do_facet mgs "seq -f 'c%g' $large_i | xargs -n1 $LCTL nodemap_add"
wait_nm_sync c$large_i admin_nodemap
do_facet mgs "seq -f 'c%g' $large_i | xargs -n1 $LCTL nodemap_del"
wait_nm_sync c$large_i admin_nodemap
}
run_test 26 "test transferring very large nodemap"
is_multi_fileset_supported() {
local facet=${1:-"mgs"}
local ver
if [[ $facet == "mgs" ]]; then
ver=$MGS_VERSION
elif [[ $facet == mds* ]]; then
ver=$MDS1_VERSION
elif [[ $facet == ost* ]]; then
ver=$OST1_VERSION
else
error "unknown facet $facet"
fi
(( ver >= $(version_code 2.16.57) ))
}
do_facet_check_fileset() {
local facet=$1
local nm=$2
local fset_check=$3
local fset_type=${4:-"primary"}
local fset_ro=${5:-"rw"}
if [[ $fset_type != "primary" && $fset_type != "alternate" ]]; then
error "unknown fileset type $fset_type"
fi
if ! is_multi_fileset_supported $facet; then
do_facet $facet $LCTL get_param -n nodemap.${nm}.fileset
elif [[ $fset_ro == "ro" ]]; then
do_facet $facet "$LCTL get_param nodemap.${nm}.fileset | \
awk -F '[[:blank:]]+|,' '/${fset_type}/ { \
if (\\\$4 == \\\"$fset_check\\\" && \\\$7 == \\\"ro\\\" ) \
print \\\$4 }'"
else
do_facet $facet "$LCTL get_param nodemap.${nm}.fileset | \
awk -F '[[:blank:]]+|,' '/${fset_type}/ { \
if (\\\$4 == \\\"$fset_check\\\" && \\\$7 != \\\"ro\\\" ) \
print \\\$4 }'"
fi
}
wait_update_facet_fileset() {
local facet=$1
local nm=$2
local fset_check=$3
local fset_expected=$4
local fset_type=${5:-"primary"}
local error_msg="fileset not cleared on $nm nodemap"
if [[ -n $fset_expected ]]; then
error_msg="fileset $fset_check not set on $nm nodemap"
fi
if [[ $fset_type != "primary" && $fset_type != "alternate" ]]; then
error "unknown fileset type $fset_type"
fi
# use fileset old syntax for pre multi fileset servers
if ! is_multi_fileset_supported $facet; then
if [[ $fset_type == "alternate" ]]; then
error "alt filesets not supported on $facet < 2.16.57"
fi
wait_update_facet $facet \
"$LCTL get_param nodemap.${nm}.fileset" \
"nodemap.${nm}.fileset=$fset_expected" ||
error $error_msg
return $?
fi
wait_update_facet $facet "$LCTL get_param nodemap.${nm}.fileset | \
awk '/${fset_type}/ { if (\\\$3 == \\\"$fset_check\\\") print \\\$3 }'" \
"$fset_expected" || error $error_msg
}
wait_nm_sync_fileset() {
local nm=$1
local fset_check=$2
local fset_expected=$3
local fset_type=${4:-"primary"}
local fset_ro=${5:-false}
local awk_expr
if [[ $fset_type != "primary" && $fset_type != "alternate" ]]; then
error "unknown fileset type $fset_type"
fi
# use fileset old syntax for pre multi fileset servers
if ! is_multi_fileset_supported; then
if [[ $fset_type == "alternate" || $fset_ro == true ]]; then
error "alt filesets or read-only filesets not supported on servers"
fi
wait_nm_sync $nm fileset "nodemap.${nm}.fileset=$fset_expected"
return $?
fi
# check if ro flag is set for given fileset and print the fileset if yes
if $fset_ro; then
awk_expr="awk -F '[[:blank:]]+|,' '/$fset_type/ { \
if (\$4 == \"$fset_check\" && \$7 == \"ro\") \
print \$4 }'"
else
awk_expr="awk -F '[[:blank:]]+|,' '/$fset_type/ { \
if (\$4 == \"$fset_check\" && \$7 != \"ro\") \
print \$4 }'"
fi
wait_nm_sync $nm fileset "$fset_expected" "inactive" "$awk_expr"
}
wait_nm_sync_fileset_cleared() {
local nm=$1
local fset_type=${2:-"primary"}
wait_nm_sync_fileset $nm "" "" $fset_type
}
nodemap_clear_filesets_and_wait() {
local nm=$1
echo "Currently set filesets on nodemap '$nm':"
do_facet mgs $LCTL get_param nodemap.$nm.fileset
if is_multi_fileset_supported; then
do_facet mgs $LCTL nodemap_fileset_del --name $nm --all
wait_nm_sync_fileset_cleared $nm
fi
}
nodemap_exercise_fileset_cleanup() {
# Already mounted clients are skipped in zconf_mount_clients()
for client in "${clients_arr[@]}"; do
zconf_mount_clients $client $MOUNT $MOUNT_OPTS ||
error "unable to mount client $client"
done
wait_ssk
}
stopall_restart_servers() {
stopall || error "unable to stop"
LOAD_MODULES_REMOTE=true unload_modules ||
error "unable to unload modules"
LOAD_MODULES_REMOTE=true load_modules ||
error "unable to load modules"
mountmgs || error "unable to start mgs"
mountmds || error "unable to start mds"
mountoss || error "unable to start oss"
}
nodemap_exercise_fileset() {
local have_persistent_fset_cmd=false
local check_proj=true
local loop=0
local nm="$1"
local subdir="subdir_${nm}"
local subsubdir="subsubdir_${nm}"
(( $MDS1_VERSION >= $(version_code 2.14.52) )) || check_proj=false
# when "have_persistent_fset_cmd" is true, "lctl nodemap_set_fileset"
# is persistent, otherwise "lctl set_param -P" must be used
if (( $MGS_VERSION >= $(version_code 2.16.51) )); then
have_persistent_fset_cmd=true
subdir="thisisaverylongsubdirtotestlongfilesetsandtotestmultiplefilesetfragmentsonthenodemapiam_${nm}"
fi
# setup
if [[ "$nm" == "default" ]]; then
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
check_proj=false
else
nodemap_test_setup
fi
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
else
# will conflict with SK's nodemaps
trap "fileset_test_cleanup $nm" EXIT
fi
fileset_test_setup "$nm"
# add fileset info to $nm nodemap
if $have_persistent_fset_cmd; then
do_facet mgs $LCTL nodemap_set_fileset --name $nm \
--fileset "/${subdir}" ||
error "can't set fileset to $nm nodemap on MGS"
# check fileset is set on local mgs node
wait_update_facet_fileset mgs $nm "/$subdir" "/$subdir" \
"primary"
else
if ! combined_mgs_mds; then
do_facet mgs $LCTL set_param \
nodemap.${nm}.fileset=/${subdir} ||
error "can't set fileset /${subdir} to $nm nodemap on MGS"
fi
do_facet mgs $LCTL set_param -P \
nodemap.${nm}.fileset=/${subdir} ||
error "can't set fileset /${subdir} to $nm nodemap on servers"
fi
# check fileset is set on remote nodes
wait_nm_sync_fileset $nm "/$subdir" "/$subdir" "primary"
if $check_proj; then
do_facet mgs $LCTL nodemap_modify --name $nm \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name $nm \
--property trusted --value 0
do_facet mgs $LCTL nodemap_modify --name $nm \
--property map_mode --value projid
do_facet mgs $LCTL nodemap_add_idmap --name $nm \
--idtype projid --idmap 1:1
do_facet mgs $LCTL nodemap_modify --name $nm \
--property deny_unknown --value 1
wait_nm_sync $nm deny_unknown
fi
# re-start all components to verify persistence of fileset after restart
stopall_restart_servers
stack_trap nodemap_exercise_fileset_cleanup EXIT
# mount a single client for fileset testing and remount
# the remaining clients later.
# set some generic fileset to trigger SSK code
export FILESET=/
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to remount client ${clients_arr[0]}"
unset FILESET
wait_ssk
# test mount point content
do_node ${clients_arr[0]} test -f $MOUNT/this_is_$subdir ||
error "fileset not taken into account"
if $check_proj; then
do_node ${clients_arr[0]} $LFS setquota -p 1 -b 10000 -B 11000 \
-i 0 -I 0 $MOUNT || error "setquota -p 1 failed"
do_node ${clients_arr[0]} $LFS setquota -p 2 -b 10000 -B 11000 \
-i 0 -I 0 $MOUNT && error "setquota -p 2 should fail"
fi
# re-mount client with sub-subdir
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
export FILESET=/$subsubdir
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to remount client ${clients_arr[0]}"
unset FILESET
wait_ssk
# test mount point content
do_node ${clients_arr[0]} test -f $MOUNT/this_is_$subsubdir ||
error "subdir of fileset not taken into account"
# remove fileset info from nodemap
do_facet mgs $LCTL nodemap_set_fileset --name $nm --fileset clear ||
error "unable to delete fileset info on $nm nodemap"
# check whether fileset was removed on mgs
wait_update_facet_fileset mgs $nm "/$subdir" "" "primary"
if ! $have_persistent_fset_cmd; then
do_facet mgs $LCTL set_param -P nodemap.${nm}.fileset=clear ||
error "unable to reset fileset info on $nm nodemap"
fi
# check whether fileset was removed on remote nodes
wait_nm_sync_fileset $nm "/$subdir" "" "primary"
if ! $have_persistent_fset_cmd; then
do_facet mgs $LCTL set_param -P -d nodemap.${nm}.fileset ||
error "unable to remove fileset rule on $nm nodemap"
fi
# re-mount client
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to remount client ${clients_arr[0]}"
wait_ssk
# test mount point content
if ! $(do_node ${clients_arr[0]} test -d $MOUNT/$subdir); then
ls $MOUNT
error "fileset not cleared on $nm nodemap"
fi
# back to non-nodemap setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
fi
fileset_test_cleanup "$nm"
if [[ "$nm" == "default" ]]; then
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0
do_facet mgs $LCTL nodemap_activate 0
wait_nm_sync active 0
trap 0
export SK_UNIQUE_NM=false
else
nodemap_test_cleanup
fi
# The fileset cleanup trap is reset during nodemap clean up.
# Call fileset cleanup to restart all shut down clients
nodemap_exercise_fileset_cleanup
}
test_27a() {
(( $MDS1_VERSION < $(version_code 2.11.50) )) &&
skip "Need MDS >= 2.11.50"
for nm in "default" "c0"; do
if [[ "$nm" == "default" && "$SHARED_KEY" == "true" ]]; then
echo "Skipping nodemap $nm with SHARED_KEY"
continue
fi
echo "Exercising fileset for nodemap $nm"
nodemap_exercise_fileset "$nm"
done
}
run_test 27a "test fileset in various nodemaps"
test_27aa() { #LU-17922
local idmap
local id=500
(( $MDS1_VERSION >= $(version_code v2_15_64-86-g8445f7b92f) )) ||
skip "need MDS >= 2.15.64.86 for nodemap range"
do_facet mgs $LCTL nodemap_add Test17922 ||
error "unable to add Test17922 as nodemap"
stack_trap "do_facet mgs $LCTL nodemap_del Test17922 || true"
do_facet mgs $LCTL nodemap_add_idmap --name Test17922 \
--idtype uid --idmap 500-509:10000-10009 ||
error "unable to add idmap range 500-509:10000-10009"
idmap=$(do_facet mgs $LCTL get_param nodemap.Test17922.idmap | grep idtype)
while IFS= read -r idmap; do
if (( $id <= 509 )); then
[[ "$idmap" == *"client_id: $id"* ]] ||
error "could not find 'client_id: ${id}' inside of ${idmap}"
fi
((id++))
done < <(echo "$idmap")
do_facet mgs $LCTL nodemap_del_idmap --name Test17922 \
--idtype uid --idmap 505-509:10005 ||
error "cannot delete idmap range 505-509:10005"
id=500
idmap=$(do_facet mgs $LCTL get_param nodemap.Test17922.idmap | grep idtype)
while IFS= read -r idmap; do
if (( $id <= 504 )); then
[[ "$idmap" == *"client_id: $id"* ]] ||
error "could not find 'client_id: ${id}' inside of ${idmap}"
else
[[ "$idmap" =~ "client_id: $id" ]] &&
error "found 'client_id: $id' in $idmap"
fi
((id++))
done < <(echo "$idmap")
do_facet mgs $LCTL nodemap_del_idmap --name Test17922 \
--idtype uid --idmap 500-504:10000
#expected error, invalid secondary range supplied
do_facet mgs $LCTL nodemap_add --name Test17922 \
--idtype uid --idmap 500-509:10000-10010 &&
error "Invalid range 10000-10010 was added"
(( $(do_facet mgs $LCTL get_param nodemap.Test17922.idmap |
grep -c idtype) == 0 )) ||
error "invalid range 10000-10010 supplied and passed"
do_facet mgs $LCTL nodemap_del Test17922 ||
error "failed to remove nodemap Test17922"
}
run_test 27aa "test nodemap idmap range"
test_27ab() { #LU-18109
local offset_start=100000
local offset_limit=200000
local nid=1.1.1.1@tcp777
local activedefault
local nm1=Test18109
local nm2=OffsetTest
local squash=65534
local id_start=500
local expected
local id=500
local idmap
local offset
(( MDS1_VERSION > $(version_code 2.16.50.170) )) ||
skip "need MDS > 2.16.50.170 for nodemap range offset"
do_facet mgs $LCTL nodemap_add $nm1 ||
error "unable to add $nm1 as nodemap"
stack_trap "do_facet mgs $LCTL nodemap_del $nm1 || true"
do_facet mgs $LCTL nodemap_add $nm2 ||
error "unable to add $nm2 as nodemap"
stack_trap "do_facet mgs $LCTL nodemap_del $nm2 || true"
do_facet mgs $LCTL nodemap_add_offset --name $nm1 \
--offset $offset_start --limit $offset_limit ||
error "cannot set offset $offset_start-$((offset_start+offset_limit-1)) for $nm1"
#expected error, invalid offset range supplied
do_facet mgs $LCTL nodemap_add_offset --name $nm2 \
--offset $((offset_start+50000)) --limit 100000 &&
error "setting offset $((offset_start+50000))-249999 on $nm2 should fail"
do_facet mgs $LCTL nodemap_add_idmap --name $nm1 \
--idtype uid --idmap 500-509:0-9 ||
error "unable to add idmap range 500-509:0-9"
idmap=$(do_facet mgs $LCTL get_param nodemap.$nm1.idmap |
grep idtype)
while IFS= read -r idmap; do
if (( $id <= 509 )); then
[[ "$idmap" == *"client_id: $id"* ]] ||
error "could not find 'client_id: ${id}' inside of ${idmap}"
fi
((id++))
done < <(echo "$idmap")
do_facet mgs $LCTL nodemap_add_range --name $nm1 --range $nid ||
error "Add range $nid to $nm1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property admin --value 1 ||
error "Setting admin=1 on $nm1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property trusted --value 1 ||
error "Setting trusted=1 on $nm1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property squash_uid --value $squash ||
error "Setting squash_uid=$squash on $nm1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property squash_gid --value $squash ||
error "Setting squash_gid=$squash on $nm1 failed"
activedefault=$(do_facet mgs $LCTL get_param -n nodemap.active)
if ((activedefault != 1)); then
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
stack_trap cleanup_active EXIT
fi
if (( MDS1_VERSION >= $(version_code 2.16.51.45) )); then
# with admin=1, we expect root to be offset
id=0
expected=$offset_start
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
# with trusted=1, we expect ids to be offset
id=$((id_start+1))
expected=$((offset_start+id_start+1))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property trusted --value 0 ||
error "Setting trusted=0 on $nm1 failed"
# with trusted=0, we expect uid to be mapped+offset,
# gid to be squashed+offset
expected=$((offset_start+1))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
expected=$((offset_start+squash))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property admin --value 0 ||
error "Setting admin=0 on $nm1 failed"
# with admin=0, we expect root to be squashed+offset
id=0
expected=$((offset_start+squash))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property admin --value 1 ||
error "Setting admin=1 on $nm1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property trusted --value 1 ||
error "Setting trusted=1 on $nm1 failed"
fi
do_facet mgs $LCTL nodemap_del_idmap --name $nm1 \
--idtype uid --idmap 500-509:0 ||
error "cannot delete idmap range 500-509:0"
#expected error, invalid secondary range supplied
do_facet mgs $LCTL nodemap_add_idmap --name $nm1 \
--idtype uid --idmap 500-509:200000-200010 &&
error "Invalid range 200000-200010 was supplied"
(( $(do_facet mgs $LCTL get_param nodemap.$nm1.idmap |
grep -c idtype) == 0 )) ||
error "invalid range 200000-200010 supplied and passed"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep start_uid)
[[ "$offset" == *"start_uid: $offset_start"* ]] ||
error "expected start_uid of $offset_start not found before remounting"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep limit_uid)
[[ "$offset" == *"limit_uid: $offset_limit"* ]] ||
error "expected limit_uid of $offset_limit not found before remounting"
if (( MDS1_VERSION >= $(version_code 2.16.51.45) )); then
# with admin=1, we expect root to be offset
id=0
expected=$offset_start
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
# with trusted=1, we expect ids to be offset
id=$((id_start+1))
expected=$((offset_start+id_start+1))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property trusted --value 0 ||
error "Setting trusted=0 on $nm1 failed"
# with trusted=0, we expect uid to be squashed+offset
expected=$((offset_start+squash))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property admin --value 0 ||
error "Setting admin=0 on $nm1 failed"
# with admin=0, we expect root to be squashed+offset
id=0
expected=$((offset_start+squash))
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype uid --id $id)
((idmap == expected)) ||
error "uid $id should be mapped to $expected"
idmap=$(do_facet mgs $LCTL nodemap_test_id --nid $nid \
--idtype gid --id $id)
((idmap == expected)) ||
error "gid $id should be mapped to $expected"
fi
stopall || error "failed to unmount servers"
setupall || error "failed to remount servers"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep start_uid)
[[ "$offset" == *"start_uid: $offset_start"* ]] ||
error "expected start_uid of $offset_start not found after remounting"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep limit_uid)
[[ "$offset" == *"limit_uid: $offset_limit"* ]] ||
error "expected limit_uid of $offset_limit not found after remounting"
do_facet mgs $LCTL nodemap_del_offset --name $nm1 ||
error "cannot del offset from $nm1"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep start_uid)
[[ "$offset" == *"start_uid: 0"* ]] ||
error "expected start_uid 0, found $offset"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep limit_uid)
[[ "$offset" == *"limit_uid: 0"* ]] ||
error "expected limit_uid 0, found $offset"
stopall || error "failed to unmount servers"
setupall || error "failed to remount servers"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep start_uid)
[[ "$offset" == *"start_uid: 0"* ]] ||
error "expected start_uid 0, found $offset after remounting"
offset=$(do_facet mgs $LCTL get_param nodemap.$nm1.offset |
grep limit_uid)
[[ "$offset" == *"limit_uid: 0"* ]] ||
error "expected limit_uid 0, found $offset after remounting"
do_facet mgs $LCTL nodemap_del $nm1 ||
error "failed to remove nodemap $nm1"
do_facet mgs $LCTL nodemap_del $nm2 ||
error "failed to remove nodemap $nm2"
}
run_test 27ab "test nodemap idmap offset"
cleanup_27ac() {
local nm=$1
do_facet mgs $LCTL nodemap_del $nm
wait_nm_sync $nm id ''
# restart clients
nodemap_exercise_fileset_cleanup
}
test_27ac() {
local nm="test27ac_nm"
local fileset_llog="/llog_fileset"
local fileset_iam="/iam_fileset"
is_multi_fileset_supported "mds1" ||
skip "Need MDS >= 2.16.57 llog fileset compatibility"
if [[ $(facet_active_host mgs) == $(facet_active_host mds) &&
$(facet_active_host mgs) == $(facet_active_host ost1) ]]; then
skip "local mode not supported"
fi
do_facet mgs $LCTL nodemap_add $nm || error "unable to add $nm nodemap"
stack_trap "cleanup_27ac $nm" EXIT
# set iam fileset
do_facet mgs $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset_iam ||
error "unable to set fileset $fileset_iam on $nm"
wait_nm_sync_fileset $nm "$iam_fileset" "$iam_fileset" "primary" ||
error "fileset $iam_fileset not synced"
# quickly delete and re-add nodemap in one synchronization step
do_facet mgs "$LCTL nodemap_del $nm ; $LCTL nodemap_add $nm" ||
error "unable to del and add $nm nodemap"
# 1. IAM fileset should be removed
wait_nm_sync_fileset $nm "$iam_fileset" "" "primary" ||
error "fileset not cleared"
# set llog fileset
do_facet mgs $LCTL set_param nodemap.$nm.fileset=$fileset_llog ||
error "unable to set fileset $fileset_llog on $nm locally"
do_facet mgs $LCTL set_param -P nodemap.$nm.fileset=$fileset_llog ||
error "unable to set fileset $fileset_llog on $nm persistently"
wait_nm_sync_fileset $nm "$llog_fileset" "$llog_fileset" "primary" ||
error "fileset $llog_fileset not synced"
# re-start all components to verify persistence of fileset after restart
stopall_restart_servers
# 2. Verify llog fileset is still set
wait_update_facet_fileset mds1 $nm "$fileset_llog" \
"$fileset_llog" "primary" ||
error "fileset $fileset_llog shouldn't be removed after restart"
# overwrite llog fileset with iam fileset
do_facet mgs $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset_iam ||
error "unable to set fileset $fileset_iam on $nm"
wait_nm_sync_fileset $nm "$iam_fileset" "$iam_fileset" "primary" ||
error "fileset $iam_fileset not synced"
# 3. setting llog fileset should be denied. We omit set_param -P since
# it follows the same logic but can't be verified as the error is
# happens on the other server nodes which is not returned to the mgs
do_facet mgs $LCTL set_param nodemap.$nm.fileset=$fileset_llog &&
error "should not be able to set fileset $fileset_llog on $nm"
# reset fileset (allows setting an llog fileset)
do_facet mgs $LCTL nodemap_set_fileset --name $nm --fileset clear ||
error "unable to clear fileset on $nm"
wait_nm_sync_fileset $nm "$iam_fileset" "" "primary" ||
error "fileset not cleared"
# 4. Restart and verify fileset is still cleared
stopall_restart_servers
wait_nm_sync_fileset $nm "$iam_fileset" "" "primary" ||
error "fileset not cleared"
# 5. Verify fileset can be set
do_facet mgs $LCTL set_param nodemap.$nm.fileset=$fileset_llog ||
error "unable to set fileset $fileset_llog on $nm locally"
do_facet mgs $LCTL set_param -P nodemap.$nm.fileset=$fileset_llog ||
error "unable to set fileset $fileset_llog on $nm persistently"
wait_nm_sync_fileset $nm "$llog_fileset" "$llog_fileset" "primary" ||
error "fileset $llog_fileset not synced"
# delete and re-add nodemap
do_facet mgs "$LCTL nodemap_del $nm ; $LCTL nodemap_add $nm" ||
error "unable to del and add $nm nodemap"
# 6. llog fileset should be removed
wait_nm_sync_fileset $nm "$llog_fileset" "" "primary" ||
error "fileset not cleared"
}
run_test 27ac "test nodemap llog and IAM fileset compatibility"
test_27b() { #LU-10703
local i
local fset
(( MDS1_VERSION < $(version_code 2.11.50) )) &&
skip "Need MDS >= 2.11.50"
(( MDSCOUNT < 2 )) && skip "needs >= 2 MDTs"
nodemap_test_setup
trap nodemap_test_cleanup EXIT
# Add the nodemaps and set their filesets
for ((i = 1; i <= MDSCOUNT; i++)); do
do_facet mgs $LCTL nodemap_del nm$i 2>/dev/null
do_facet mgs $LCTL nodemap_add nm$i ||
error "add nodemap nm$i failed"
wait_nm_sync nm$i "" "" "-N"
do_facet mgs \
$LCTL set_param nodemap.nm$i.fileset=/dir$i ||
error "set nm$i.fileset=/dir$i failed on MGS"
do_facet mgs $LCTL set_param -P nodemap.nm$i.fileset=/dir$i ||
error "set nm$i.fileset=/dir$i failed on servers"
wait_nm_sync_fileset "nm$i" "/dir$i" "/dir$i" "primary"
# set a property to check that the nodemap have been synced
# as the sync disables the set_iam flag for llog filesets
do_facet mgs $LCTL nodemap_modify --name nm$i \
--property admin --value 1 || error "set admin failed"
wait_nm_sync nm$i admin_nodemap
done
# Check if all the filesets are correct
for ((i = 1; i <= MDSCOUNT; i++)); do
fset=$(do_facet_check_fileset "mds$i" "nm$i" "/dir$i")
[[ $fset == "/dir$i" ]] ||
error "nm$i.fileset $fset != /dir$i on mds$i"
do_facet mgs $LCTL set_param -P -d nodemap.nm$i.fileset ||
error "unable to remove fileset rule for nm$i nodemap"
do_facet mgs $LCTL nodemap_del nm$i ||
error "delete nodemap nm$i failed"
done
nodemap_test_cleanup
}
run_test 27b "The new nodemap won't clear the old nodemap's fileset"
test_27c() {
local nm
local nm_tmp
local i
local fset
local prim_fileset
local alt_fileset
is_multi_fileset_supported ||
skip "Need MGS >= 2.16.57 for multiple filesets"
# clients are re-mounted later when all filesets are removed
stack_trap nodemap_exercise_fileset_cleanup EXIT
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
else
# will conflict with SK's nodemaps
stack_trap nodemap_test_cleanup EXIT
fi
nm="c0"
nm_tmp="c0_tmp"
prim_fileset="/this_is_a_primary_fileset"
alt_fileset="/this_is_an_alternate_fileset"
nodemap_test_setup
do_facet mgs $LCTL nodemap_fileset_add --name $nm \
--fileset "$prim_fileset" ||
error "cannot add prim fileset $prim_fileset"
stack_trap "nodemap_clear_filesets_and_wait $nm" EXIT
# add 255 alternate filesets
# each longer than the previous one, up to 941 characters
for ((i = 1; i < 256; i++)); do
alt_fileset="${alt_fileset}${i}_"
do_facet mgs $LCTL nodemap_fileset_add --alt --name $nm \
--fileset "$alt_fileset" ||
error "cannot add alt fileset $alt_fileset"
done
wait_nm_sync_fileset $nm "$alt_fileset" "$alt_fileset" "alternate"
alt_fileset="${alt_fileset}OVERFLOW_"
do_facet mgs $LCTL nodemap_fileset_add --alt --name $nm \
--fileset "$alt_fileset" &&
error "shouldn't be able to add alt fileset $alt_fileset"
# re-start all components to verify persistence of fileset after restart
stopall_restart_servers
alt_fileset="/this_is_an_alternate_fileset"
for ((i = 1; i < 256; i++)); do
alt_fileset="${alt_fileset}${i}_"
do_facet mgs $LCTL nodemap_fileset_del --name $nm \
--fileset "$alt_fileset" ||
error "cannot del alt fileset $alt_fileset"
done
wait_nm_sync_fileset $nm "$alt_fileset" "" "alternate"
# primary fileset should still be present
wait_nm_sync_fileset $nm "$prim_fileset" "$prim_fileset" "primary"
do_facet mgs $LCTL nodemap_fileset_del --name $nm \
--fileset "$prim_fileset" ||
error "cannot del prim fileset $prim_fileset"
wait_nm_sync_fileset $nm "$prim_fileset" "" "primary"
fset=$(do_facet mds1 $LCTL get_param nodemap.${nm}.fileset)
grep -E 'primary|alternate' <<< $fset &&
error "filesets '$fset' not empty"
# test that filesets are implicitly removed on nodemap_del
do_facet mgs $LCTL nodemap_add $nm_tmp ||
error "cannot add nodemap $nm_tmp"
do_facet mgs $LCTL nodemap_fileset_add --name $nm_tmp \
--fileset "$prim_fileset" ||
error "cannot add prim fileset $prim_fileset to nodemap $nm_tmp"
do_facet mgs $LCTL nodemap_fileset_add --alt --name $nm_tmp \
--fileset "$alt_fileset" ||
error "cannot add alt fileset $alt_fileset to nodemap $nm_tmp"
wait_nm_sync_fileset $nm_tmp "$alt_fileset" "$alt_fileset" "alternate"
do_facet mgs $LCTL nodemap_del $nm_tmp ||
error "cannot del nodemap $nm_tmp"
wait_nm_sync $nm_tmp id ''
# test clear fileset functionality
do_facet mgs $LCTL nodemap_fileset_add --name $nm \
--fileset "$prim_fileset" ||
error "cannot add prim fileset $prim_fileset"
alt_fileset="/this_is_an_alternate_fileset"
for ((i = 1; i < 16; i++)); do
alt_fileset="${alt_fileset}${i}_"
do_facet mgs $LCTL nodemap_fileset_add --alt --name $nm \
--fileset "$alt_fileset" ||
error "cannot add alt fileset $alt_fileset"
done
wait_nm_sync_fileset $nm "$alt_fileset" "$alt_fileset" "alternate"
nodemap_clear_filesets_and_wait $nm
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
fi
# nodemap cleanup implicitly disables previous stack_traps
nodemap_test_cleanup
nodemap_exercise_fileset_cleanup
}
run_test 27c "test alternate fileset varying length and limits"
multi_fileset_test_setup() {
local nm=$1
local base_dir
local teststring="teststring"
if [[ -n "$FILESET" && -z "$SKIP_FILESET" ]]; then
cleanup_mount $MOUNT
FILESET="" zconf_mount_clients $CLIENTS $MOUNT
wait_ssk
fi
do_facet mgs $LCTL nodemap_modify --name $nm --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name $nm --property trusted \
--value 1
wait_nm_sync $nm trusted_nodemap
base_dir=$MOUNT
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${fs_root}" ||
error "unable to create file in $base_dir"
base_dir="${MOUNT}/${mult_fset_root}/${subd_no_fset}"
do_node ${clients_arr[0]} mkdir -p $base_dir ||
error "unable to create dir $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${prefix}${subd_no_fset}" ||
error "unable to create file in $base_dir"
# setup primary fileset directories
base_dir="${MOUNT}/${mult_fset_root}/${subd_p}"
do_node ${clients_arr[0]} \
mkdir -p "${base_dir}/{${subsubd_p0},${subsubd_p1}}" ||
error "unable to create subdirs in $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${prefix}${subd_p}" ||
error "unable to create file in $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${subsubd_p0}/${prefix}${subsubd_p0}" ||
error "unable to create file in ${base_dir}/${subsubd_p0}"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${subsubd_p1}/${prefix}${subsubd_p1}" ||
error "unable to create file in ${base_dir}/${subsubd_p1}"
# setup alternate fileset directory
base_dir="${MOUNT}/${mult_fset_root}/${subd_alt_foo}"
do_node ${clients_arr[0]} mkdir -p $base_dir ||
error "unable to create dir $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${prefix}${subd_alt_foo}" ||
error "unable to create file in $base_dir"
# setup alternate fileset subdirectories
base_dir="${MOUNT}/${mult_fset_root}/${subd_alt_home}"
do_node ${clients_arr[0]} \
mkdir -p "${base_dir}/${subsubd_h0}" ||
error "unable to create subdirs in $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${prefix}${subd_alt_home}" ||
error "unable to create file in $base_dir"
do_node ${clients_arr[0]} \
"echo $teststring > ${base_dir}/${subsubd_h0}/${prefix}${subsubd_h0}" ||
error "unable to create file in $base_dir"
# flush MDT locks to make sure they are reacquired before test
do_node ${clients_arr[0]} $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear
}
multi_fileset_test_cleanup() {
local nm=$1
# stop all clients as they may be mounted as read-only
zconf_umount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
do_facet mgs $LCTL nodemap_modify --name $nm --property admin --value 1
do_facet mgs $LCTL nodemap_modify --name $nm --property trusted \
--value 1
wait_nm_sync $nm trusted_nodemap
# make sure any filesets are cleared before mounting the client
nodemap_clear_filesets_and_wait $nm
# ensure client 0 is running for cleanup
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to mount client ${clients_arr[0]}"
wait_ssk
if [[ -n "$FILESET" && -z "$SKIP_FILESET" ]]; then
cleanup_mount $MOUNT
zconf_mount_clients $CLIENTS $MOUNT
wait_ssk
fi
}
multi_fileset_test_success() {
local mount_subdir=$1
local testfile=$2
local readonly=${3:-false}
local tmpfile="${testfile}_tmp_test"
local teststring="teststring"
local tmp
FILESET=$mount_subdir \
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "unable to mount client ${clients_arr[0]}"
wait_ssk
echo "Current file system tree under fileset dir:"
do_node ${clients_arr[0]} tree ${MOUNT}
do_node ${clients_arr[0]} test -f $testfile ||
error "cannot access $testfile in mount subdir $mount_subdir"
if ! $readonly; then
do_node ${clients_arr[0]} "findmnt $MOUNT --output=options -n -f" \
| grep -q "rw," ||
error "should be rw mount"
do_node ${clients_arr[0]} "$LFS setstripe -c 1 $tmpfile" ||
error "unable to create $tmpfile on rw mount"
do_node ${clients_arr[0]} "echo $teststring >> $tmpfile" ||
error "unable to write to $tmpfile on rw mount"
tmp=$(do_node ${clients_arr[0]} cat $tmpfile)
[[ $tmp != $teststring ]] &&
error "unable to read $tmpfile from rw mount"
do_node ${clients_arr[0]} "rm $tmpfile" ||
error "unable to remove $tmpfile on rw mount"
else
do_node ${clients_arr[0]} "findmnt $MOUNT --output=options -n -f" \
| grep -q "ro," ||
error "should be ro mount"
do_node ${clients_arr[0]} "$LFS setstripe -c 1 $tmpfile" &&
error "should not be able to create $tmpfile on ro mount"
# $testfile is created in multi_fileset_test_setup()
tmp=$(do_node ${clients_arr[0]} cat $testfile)
[[ $tmp == $teststring ]] ||
error "unable to read $tmpfile from ro mount"
fi
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
}
multi_fileset_test_failure() {
local mount_subdir=$1
FILESET=$mount_subdir \
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS &&
error "shouldn't be able to mount $mount_subdir"
}
multi_fileset_test_run() {
local nm=$1
local ro=${2:-false}
local ro_fileset=""
is_multi_fileset_supported ||
skip "Need MGS >= 2.16.57 for multiple filesets"
local mult_fset_root=$tdir
local fs_root=$tfile
local prefix="this_is_"
local subd_no_fset="no_fset"
local subd_p="prim"
local subsubd_p0="subsubdir_prim0"
local subsubd_p1="subsubdir_prim1"
local subd_alt_foo="alt_foo"
local subd_alt_home="alt_home"
local subsubd_h0="subsubdir_user0"
if $ro; then
ro_fileset="--ro"
fi
stack_trap nodemap_test_cleanup EXIT
nodemap_test_setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
else
# will conflict with SK's nodemaps
stack_trap "multi_fileset_test_cleanup $nm" EXIT
fi
multi_fileset_test_setup $nm
# stop all clients
zconf_umount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
# case 1 (test for success): nodemap active with no filesets
# client can mount "/"
multi_fileset_test_success "/" "${MOUNT}/${fs_root}"
# case 2 (test for success): nodemap active but no filesets specified
# client can mount ${subddir_no_fileset}
multi_fileset_test_success "/${mult_fset_root}/${subd_no_fset}" \
"${MOUNT}/${prefix}${subd_no_fset}"
# setup filesets
do_facet mgs $LCTL nodemap_fileset_add $ro_fileset --name $nm \
--fileset "/${mult_fset_root}/${subd_p}" ||
error "unable to add primary fileset (1)"
do_facet mgs $LCTL nodemap_fileset_add --alt $ro_fileset --name $nm \
--fileset "/${mult_fset_root}/${subd_alt_foo}" ||
error "unable to add alt fileset (1)"
do_facet mgs $LCTL nodemap_fileset_add --alt $ro_fileset --name $nm \
--fileset "/${mult_fset_root}/${subd_alt_home}" ||
error "unable to add alt fileset (2)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/${subd_alt_home}" \
"/${mult_fset_root}/${subd_alt_home}" "alternate" $ro
# print for future reference
do_facet mds1 $LCTL get_param nodemap.${nm}.fileset
# case 3 (test for failure): Invalid mount path that doesn't exist
# Client should not be able to mount 'some_subdir_that_doesnt_exist'
multi_fileset_test_failure "/some_subdir_that_doesnt_exist"
# case 4 (test for failure): valid mount path not in alt fileset
# Client should not be able mount ${subd_no_fset}
multi_fileset_test_failure "/${mult_fset_root}/${subd_no_fset}"
# case 5 (test for success): no mount path set on client
# mount should be in the primary fileset => $subd_p
multi_fileset_test_success "/" "${MOUNT}/${prefix}${subd_p}" $ro
# case 6 (test for success): exact primary mount path set on client
# mount should be in the primary fileset => $subd_p
multi_fileset_test_success "/${mult_fset_root}/${subd_p}" \
"${MOUNT}/${prefix}${subd_p}" $ro
# case 7 (test for success): prefix primary mount path set on client
# mount should be in the primary fileset => $subd_p/$subsubd_p0
multi_fileset_test_success \
"/${mult_fset_root}/${subd_p}/${subsubd_p0}" \
"${MOUNT}/${prefix}${subsubd_p0}" $ro
# case 8 (test for success): primary fileset appending.
# mount should be in the primary fileset => $subd_p/$subsubd_p1
multi_fileset_test_success "/${subsubd_p1}" \
"${MOUNT}/${prefix}${subsubd_p1}" $ro
# case 9 (test for success): alt fileset with exact client mount
# mount should be in the alt fileset => $subd_alt_foo
multi_fileset_test_success "/${mult_fset_root}/${subd_alt_foo}" \
"${MOUNT}/${prefix}${subd_alt_foo}" $ro
# case 10 (test for success): alt fileset with prefix client mount
# mount should be in the alt fileset => $subd_alt_home/$subsubd_h0
multi_fileset_test_success \
"/${mult_fset_root}/${subd_alt_home}/${subsubd_h0}" \
"${MOUNT}/${prefix}${subsubd_h0}" $ro
# remove primary fileset and retest primary fileset cases for failure
do_facet mgs $LCTL nodemap_fileset_del --name $nm \
--fileset "/${mult_fset_root}/${subd_p}" ||
error "unable to delete primary fileset (1)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/${subd_p}" \
"" "primary" $ro
# case 11 (test for failure): no mountpoint set on client
multi_fileset_test_failure "/"
# case 12 (test for failure): prev. exact primary mount set on client
multi_fileset_test_failure "/${mult_fset_root}/${subd_p}"
# case 13 (test for failure): prev. prefix primary mount set on client
multi_fileset_test_failure \
"/${mult_fset_root}/${subd_p}/${subsubd_p0}"
# case 14 (test for failure): prev. primary fileset appending.
multi_fileset_test_failure "/${subsubd_p1}"
# remove one alt fileset and retest relevant alt fileset case
do_facet mgs $LCTL nodemap_fileset_del --name $nm \
--fileset "/${mult_fset_root}/${subd_alt_foo}" ||
error "unable to delete alt fileset (1)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/${subd_alt_foo}" \
"" "alternate" $ro
# case 15 (test for failure): prev. alt fileset with exact client mount
multi_fileset_test_failure "/${mult_fset_root}/${subd_alt_foo}"
do_facet mgs $LCTL nodemap_fileset_del --name $nm \
--fileset "/${mult_fset_root}/${subd_alt_home}" ||
error "unable to delete alt fileset (2)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/${subd_alt_home}" \
"" "alternate" $ro
# print for future reference
do_facet mds1 $LCTL get_param nodemap.${nm}.fileset
# all filesets are removed, re-test normal access
# case 16 (test for success): prev. alt fileset with prefix client mount
multi_fileset_test_success \
"/${mult_fset_root}/${subd_alt_home}/${subsubd_h0}" \
"${MOUNT}/${prefix}${subsubd_h0}"
# case 17 (test for failure): Invalid mount path that doesn't exist
# Client should not be able to mount 'some_subdir_that_doesnt_exist'
multi_fileset_test_failure "/some_subdir_that_doesnt_exist"
# case 18 (test for success): nodemap active but no filesets specified
# client can mount ${subddir_no_fileset}
multi_fileset_test_success "/${mult_fset_root}/${subd_no_fset}" \
"${MOUNT}/${prefix}${subd_no_fset}"
if (( $MGS_VERSION >= $(version_code 2.16.59) )) && $ro; then
local prim_subdir=${subd_p}/$subsubd_p0
# LU-19506
# verify mount uses the closest matched fileset (needed for ro)
# 1: prim fileset is rw and alt fileset (prim subdir) is ro
do_facet mgs $LCTL nodemap_fileset_del --name $nm --all ||
error "unable to delete all filesets (1)"
do_facet mgs $LCTL nodemap_fileset_add --name $nm \
--fileset "/${mult_fset_root}/$subd_p" ||
error "unable to add primary fileset (2)"
do_facet mgs $LCTL nodemap_fileset_add --alt --ro --name $nm \
--fileset "/${mult_fset_root}/$prim_subdir"||
error "unable to add alt fileset (3)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/$prim_subdir" \
"/${mult_fset_root}/$prim_subdir" "alternate" $ro
multi_fileset_test_success "/${mult_fset_root}/${subd_p}" \
"${MOUNT}/${prefix}${subd_p}" false
multi_fileset_test_success "/${mult_fset_root}/$prim_subdir" \
"${MOUNT}/${prefix}${subsubd_p0}" true
# exercise multi fileset mount case 4 appending mounting subdir
# to primary fileset. In this case, the appended fileset
# represents an alt fileset which means its read-only flag needs
# to be taken into account.
multi_fileset_test_success "/$subsubd_p0" \
"${MOUNT}/${prefix}${subsubd_p0}" true
# 2: prim fileset (alt subdir) is ro and alt fileset is rw
do_facet mgs $LCTL nodemap_fileset_del --name $nm --all ||
error "unable to delete all filesets (2)"
do_facet mgs $LCTL nodemap_fileset_add --ro --name $nm \
--fileset "/${mult_fset_root}/$prim_subdir"||
error "unable to add primary fileset (3)"
do_facet mgs $LCTL nodemap_fileset_add --alt --name $nm \
--fileset "/${mult_fset_root}/$subd_p" ||
error "unable to add alt fileset (4)"
wait_nm_sync_fileset $nm "/${mult_fset_root}/$subd_p" \
"/${mult_fset_root}/$subd_p" "alternate"
multi_fileset_test_success "/${mult_fset_root}/$prim_subdir" \
"${MOUNT}/${prefix}${subsubd_p0}" true
multi_fileset_test_success "/${mult_fset_root}/${subd_p}" \
"${MOUNT}/${prefix}${subd_p}" false
fi
multi_fileset_test_cleanup $nm
# back to non-nodemap setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
fi
# nodemap cleanup implicitly disables previous stack_traps
nodemap_test_cleanup
nodemap_exercise_fileset_cleanup
}
test_27d() {
local nm="c0"
multi_fileset_test_run $nm false
}
run_test 27d "test multiple filesets mounting rules (rw)"
test_27e() {
local nm="c0"
multi_fileset_test_run $nm true
}
run_test 27e "test multiple filesets mounting rules (ro)"
test_27f() {
local nm="c0"
local prim_fset="/prim_fset"
local prim_fset_new="/prim_fset_new"
local alt_fset1="/alt_fset1"
local alt_fset1_new="/alt_fset1_new"
local alt_fset2="/alt_fset2"
local invalid_fset="/invalid"
local dup_fset="/duplicate"
is_multi_fileset_supported ||
skip "Need MGS >= 2.16.57 for multiple filesets"
stack_trap nodemap_test_cleanup EXIT
nodemap_test_setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
fi
stack_trap "nodemap_clear_filesets_and_wait $nm" EXIT
do_facet mgs $LCTL nodemap_fileset_add --name $nm \
--fileset $prim_fset ||
error "unable to add fileset $prim_fset info to nodemap $nm"
do_facet mgs $LCTL nodemap_fileset_add --name $nm --fileset $alt_fset1 \
--alt ||
error "unable to add fileset $alt_fset1 info to nodemap $nm"
do_facet mgs $LCTL nodemap_fileset_add --name $nm --fileset $alt_fset2 \
--alt --ro ||
error "unable to add fileset $alt_fset2 info to nodemap $nm"
wait_nm_sync_fileset $nm $alt_fset2 $alt_fset2 "alternate" true
# Test 1: Rename primary fileset
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset --rename $prim_fset_new ||
error "failed to rename primary fileset"
wait_nm_sync_fileset $nm $prim_fset_new $prim_fset_new "primary"
# Test 2: Rename alternate fileset
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1 --rename $alt_fset1_new ||
error "failed to rename alternate fileset"
wait_nm_sync_fileset $nm $alt_fset1_new $alt_fset1_new "alternate"
# Test 3: Convert primary to alternate
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset_new --alt ||
error "failed to convert primary fileset to alt fileset"
wait_nm_sync_fileset $nm $prim_fset_new $prim_fset_new "alternate"
# Test 4: Convert alternate to primary
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1_new --prim ||
error "failed to convert alt fileset to primary"
wait_nm_sync_fileset $nm $alt_fset1_new $alt_fset1_new "primary"
# Test 5: Change access mode RW->RO for primary
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1_new --ro ||
error "failed to change primary fileset to read-only"
wait_nm_sync_fileset $nm $alt_fset1_new $alt_fset1_new "primary" true
# Test 6: Change access mode RO->RW for primary
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1_new --rw ||
error "failed to change primary fileset to read-write"
wait_nm_sync_fileset $nm $alt_fset1_new $alt_fset1_new "primary"
# Test 7: Change access mode RO->RW for alternate
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset2 --rw ||
error "failed to change alternate fileset to read-write"
wait_nm_sync_fileset $nm $alt_fset2 $alt_fset2 "alternate"
# Test 8: Change access mode RW->RO for alternate
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset2 --ro ||
error "failed to change alternate fileset to read-only"
wait_nm_sync_fileset $nm $alt_fset2 $alt_fset2 "alternate" true
# Test 9: Modify non-existent fileset (should fail)
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset "/nonexistent" --ro &&
error "modifying non-existent fileset /nonexistent should fail"
# Test 10: Modify with invalid fileset path (should fail)
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset2 --rename "invalid_no_slash" &&
error "modifying fileset with 'invalid_no_slash' should fail"
# Test 11: Modify with duplicate fileset path (should fail)
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset2 --rename $alt_fset1_new &&
error "modifying fileset to duplicate path should fail"
# Combined parameter changes
# Test 12: Change path and access mode RW->RO for primary
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1_new --rename $prim_fset --ro ||
error "failed to change path and access for primary fileset"
wait_nm_sync_fileset $nm $prim_fset $prim_fset "primary" true
# Test 13: Change path and convert primary to alternate
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset --rename $alt_fset1 --alt ||
error "failed to change path and convert primary fileset to alt"
wait_nm_sync_fileset $nm $prim_fset "" "primary"
wait_nm_sync_fileset $nm $alt_fset1 $alt_fset1 "alternate" true
# Test 14: Change path and access mode RO->RW for alternate
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset2 --rename $alt_fset1_new --rw ||
error "failed to change path and access mode for alternate fileset $alt_fset2"
wait_nm_sync_fileset $nm $alt_fset1_new $alt_fset1_new "alternate"
# Test 15: Change path and convert alternate to primary
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1_new --rename $prim_fset --prim ||
error "failed to change path and convert alt fileset to primary"
wait_nm_sync_fileset $nm $prim_fset $prim_fset "primary"
# Test 16: Change path, access mode, and prim -> alt
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset --rename $alt_fset2 --ro --alt ||
error "failed to change multiple parameters for prim fileset"
wait_nm_sync_fileset $nm $prim_fset "" "primary"
wait_nm_sync_fileset $nm $alt_fset2 $alt_fset2 "alternate" true
# Test 17: Change path, access mode, and alt -> prim
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $alt_fset1 --rename $prim_fset --rw --prim ||
error "failed to change multiple parameters for alt fileset"
wait_nm_sync_fileset $nm $alt_fset1 "" "alternate"
wait_nm_sync_fileset $nm $prim_fset $prim_fset "primary"
# Test 18: Attempt overwrite. prim exists (should fail)
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset_new --rename $prim_fset --rw --prim &&
error "should not be able to overwrite prim fileset"
# Test 19: Attempt overwrite. alt exists (should fail)
do_facet mgs $LCTL nodemap_fileset_modify --name $nm \
--fileset $prim_fset --rename $alt_fset2 --ro --alt &&
error "should not be able to overwrite alt fileset"
nodemap_clear_filesets_and_wait $nm
# back to non-nodemap setup
if $SHARED_KEY; then
export SK_UNIQUE_NM=false
fi
# nodemap cleanup implicitly disables previous stack_traps
nodemap_test_cleanup
}
run_test 27f "test nodemap_fileset_modify"
test_28() {
if ! $SHARED_KEY; then
skip "need shared key feature for this test" && return
fi
mkdir -p $DIR/$tdir || error "mkdir failed"
touch $DIR/$tdir/$tdir.out || error "touch failed"
if [ ! -f $DIR/$tdir/$tdir.out ]; then
error "read before rotation failed"
fi
# check srpc_contexts is valid YAML
$LCTL get_param -n *.*.srpc_contexts 2>/dev/null | verify_yaml ||
error "srpc_contexts is not valid YAML"
# store top key identity to ensure rotation has occurred
SK_IDENTITY_OLD=$($LCTL get_param -n *.*.srpc_contexts 2>/dev/null |
head -n 1 | awk 'BEGIN{RS=", "} $1=="expire:"{print $2}')
do_facet $SINGLEMDS lfs flushctx ||
error "could not run flushctx on $SINGLEMDS"
sleep 5
lfs flushctx || error "could not run flushctx on client"
sleep 5
# verify new key is in place
SK_IDENTITY_NEW=$($LCTL get_param -n *.*.srpc_contexts 2>/dev/null |
head -n 1 | awk 'BEGIN{RS=", "} $1=="expire:"{print $2}')
if [ $SK_IDENTITY_OLD == $SK_IDENTITY_NEW ]; then
error "key did not rotate correctly"
fi
if [ ! -f $DIR/$tdir/$tdir.out ]; then
error "read after rotation failed"
fi
}
run_test 28 "check shared key rotation method"
test_29() {
if ! $SHARED_KEY; then
skip "need shared key feature for this test" && return
fi
if [ $SK_FLAVOR != "ski" ] && [ $SK_FLAVOR != "skpi" ]; then
skip "test only valid if integrity is active"
fi
rm -r $DIR/$tdir
mkdir $DIR/$tdir || error "mkdir"
touch $DIR/$tdir/$tfile || error "touch"
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount clients"
do_node ${clients_arr[0]} "keyctl show |
awk '/lustre/ { print \\\$1 }' | xargs -IX keyctl unlink X"
OLD_SK_PATH=$SK_PATH
export SK_PATH=/dev/null
if zconf_mount_clients ${clients_arr[0]} $MOUNT; then
export SK_PATH=$OLD_SK_PATH
do_node ${clients_arr[0]} "ls $DIR/$tdir/$tfile"
if [ $? -eq 0 ]; then
error "able to mount and read without key"
else
error "able to mount without key"
fi
else
export SK_PATH=$OLD_SK_PATH
do_node ${clients_arr[0]} "keyctl show |
awk '/lustre/ { print \\\$1 }' |
xargs -IX keyctl unlink X"
fi
zconf_mount_clients ${clients_arr[0]} $MOUNT ||
error "unable to mount clients"
}
run_test 29 "check for missing shared key"
test_30() {
if ! $SHARED_KEY; then
skip "need shared key feature for this test" && return
fi
if [ $SK_FLAVOR != "ski" ] && [ $SK_FLAVOR != "skpi" ]; then
skip "test only valid if integrity is active"
fi
mkdir -p $DIR/$tdir || error "mkdir failed"
touch $DIR/$tdir/$tdir.out || error "touch failed"
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount clients"
# unload keys from ring
do_node ${clients_arr[0]} "keyctl show |
awk '/lustre/ { print \\\$1 }' | xargs -IX keyctl unlink X"
# generate key with bogus filesystem name
do_node ${clients_arr[0]} "$LGSS_SK -w $SK_PATH/$FSNAME-bogus.key \
-f $FSNAME.bogus -t client -d /dev/urandom" ||
error "lgss_sk failed (1)"
do_facet $SINGLEMDS lfs flushctx || error "could not run flushctx"
OLD_SK_PATH=$SK_PATH
export SK_PATH=$SK_PATH/$FSNAME-bogus.key
if zconf_mount_clients ${clients_arr[0]} $MOUNT; then
SK_PATH=$OLD_SK_PATH
do_node ${clients_arr[0]} "ls $DIR/$tdir/$tdir.out"
if [ $? -eq 0 ]; then
error "mount and read file with invalid key"
else
error "mount with invalid key"
fi
fi
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "unable to umount clients"
# unload keys from ring
do_node ${clients_arr[0]} "keyctl show |
awk '/lustre/ { print \\\$1 }' | xargs -IX keyctl unlink X"
rm -f $SK_PATH
SK_PATH=$OLD_SK_PATH
zconf_mount_clients ${clients_arr[0]} $MOUNT ||
error "unable to mount clients"
}
run_test 30 "check for invalid shared key"
basic_ios() {
local flvr=$1
mkdir -p $DIR/$tdir/dir0 || error "mkdir $flvr"
touch $DIR/$tdir/dir0/f0 || error "touch $flvr"
ls $DIR/$tdir/dir0 || error "ls $flvr"
dd if=/dev/zero of=$DIR/$tdir/dir0/f0 conv=fsync bs=1M count=10 \
>& /dev/null || error "dd $flvr"
rm -f $DIR/$tdir/dir0/f0 || error "rm $flvr"
rmdir $DIR/$tdir/dir0 || error "rmdir $flvr"
sync ; sync
echo 3 > /proc/sys/vm/drop_caches
}
cleanup_30b() {
# restore clients' idle_timeout
for c in ${clients//,/ }; do
param=IDLETIME_$(echo $c | cut -d'.' -f1 | sed s+-+_+g)
do_node $c "lctl set_param osc.*.idle_timeout=${!param}"
done
}
test_30b() {
local save_flvr=$SK_FLAVOR
if ! $SHARED_KEY; then
skip "need shared key feature for this test"
fi
# save clients' idle_timeout, and set all to 0 for this test,
# as we do not want connections to go idle
for c in ${clients//,/ }; do
param=IDLETIME_$(echo $c | cut -d'.' -f1 | sed s+-+_+g)
idle=$(do_node $c lctl get_param -n osc.*.idle_timeout |
head -n1)
eval export $param=\$idle
do_node $c lctl set_param osc.*.idle_timeout=0
done
stack_trap cleanup_30b EXIT
stack_trap restore_to_default_flavor EXIT
lfs mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
lfs setstripe -c -1 $DIR/$tdir/fileA ||
error "setstripe $DIR/$tdir/fileA failed"
echo 30b > $DIR/$tdir/fileA ||
error "wrtie to $DIR/$tdir/fileA failed"
for flvr in skn ska ski skpi; do
# set flavor
SK_FLAVOR=$flvr
restore_to_default_flavor || error "cannot set $flvr flavor"
SK_FLAVOR=$save_flvr
basic_ios $flvr
done
}
run_test 30b "basic test of all different SSK flavors"
cleanup_31() {
local failover_mds1=$1
# unmount client
zconf_umount $HOSTNAME $MOUNT || error "unable to umount client"
# necessary to do writeconf in order to de-register
# @${NETTYPE}999 nid for targets
KZPOOL=$KEEP_ZPOOL
export KEEP_ZPOOL="true"
stopall
LOAD_MODULES_REMOTE=true unload_modules
LOAD_MODULES_REMOTE=true load_modules
# restore mgsnid on targets
for ((num = 1; num <= $MDSCOUNT; num++)); do
do_facet mds$num $TUNEFS --erase-param mgsnode \
$(mdsdevname $num)
do_facet mds$num $TUNEFS --mgsnode=$MGSNID $(mdsdevname $num)
done
for ((num = 1; num <= $OSTCOUNT; num++)); do
do_facet ost$num $TUNEFS --erase-param mgsnode \
$(ostdevname $num)
do_facet ost$num $TUNEFS --mgsnode=$MGSNID $(ostdevname $num)
done
do_facet mds1 $TUNEFS --erase-param failover.node $(mdsdevname 1)
if [ -n "$failover_mds1" ]; then
do_facet mds1 $TUNEFS \
--servicenode=$failover_mds1 $(mdsdevname 1)
else
# If no service node previously existed, setting one in test_31
# added the no_primnode flag to the target. To remove everything
# and clear the flag, add a meaningless failnode and remove it.
do_facet mds1 $TUNEFS \
--failnode=$(do_facet mds1 $LCTL list_nids | head -1) \
$(mdsdevname 1)
do_facet mds1 $TUNEFS \
--erase-param failover.node $(mdsdevname 1)
fi
export SK_MOUNTED=false
writeconf_all
setupall || echo 1
export KEEP_ZPOOL="$KZPOOL"
}
test_31() {
local nid=$(lctl list_nids | grep ${NETTYPE} | head -n1)
local addr=${nid%@*}
local net=${nid#*@}
local net2=${NETTYPE}999
local mdsnid=$(do_facet mds1 $LCTL list_nids | head -1)
local addr1=${mdsnid%@*}
local nid2=${addr}@$net2
local addr2 failover_mds1
local all=$(all_nodes)
export LNETCTL=$(which lnetctl 2> /dev/null)
(( $MDS1_VERSION >= $(version_code 2.15.0) )) ||
skip "Need MDS >= 2.15.0"
[ -z "$LNETCTL" ] && skip "without lnetctl support." && return
local_mode && skip "in local mode."
if $SHARED_KEY; then
skip "Conflicting test with SSK"
fi
if [[ $addr1 =~ ^([0-9a-f]{0,4}:){2,7}[0-9a-f]{0,4}$ ]]; then
local tmp=$(printf "%x" $(((0x${addr1##*:} + 11) % 65536)))
addr2=${addr1%:*}:${tmp}
elif [[ $addr1 =~ ^([0-9]{1,3}\.){3,3}[0-9]{1,3}$ ]]; then
addr2=${addr1%.*}.$(((${addr1##*.} + 11) % 256))
elif [[ $addr1 =~ ^[0-9]+$ ]]; then
addr2=$((addr1 + 11))
fi
# build list of interface on nodes
for node in ${all//,/ }; do
infname=inf_$(echo $node | cut -d'.' -f1 | sed s+-+_+g)
itf=$(do_node $node $LNETCTL net show --net $net |
awk 'BEGIN{inf=0} \
{if (inf==1) { print $2; exit; } fi} /interfaces/{inf=1}')
eval $infname=\$itf
done
# backup MGSNID
local mgsnid_orig=$MGSNID
# compute new MGSNID
local mgsnid_new=${MGSNID%@*}@$net2
local tgts=$(tgts_nodes)
# save mds failover nids for restore at cleanup
failover_mds1=$(do_facet mds1 $TUNEFS --dryrun $(mdsdevname 1))
if [ -n "$failover_mds1" ]; then
failover_mds1=${failover_mds1##*Parameters:}
failover_mds1=${failover_mds1%%exiting*}
failover_mds1=$(echo $failover_mds1 | tr ' ' '\n' |
grep failover.node | cut -d'=' -f2-)
fi
stack_trap "cleanup_31 $failover_mds1" EXIT
# umount client
if [ "$MOUNT_2" ] && $(grep -q $MOUNT2' ' /proc/mounts); then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
if $(grep -q $MOUNT' ' /proc/mounts); then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
do_facet mgs "$LCTL set_param mgs.MGS.exports.clear=clear"
do_nodes $tgts "$LCTL set_param *.${FSNAME}*.exports.clear=clear"
# check exports on servers are empty for client
wait_update_facet_cond mgs \
"$LCTL get_param -N mgs.MGS.exports.* | grep $nid |
cut -d'.' -f4-" '!=' $nid
for node in ${tgts//,/ }; do
wait_update_cond $node \
"$LCTL get_param -N *.${FSNAME}*.exports.* | grep $nid |
cut -d'.' -f4-" '!=' $nid
done
do_facet mgs "$LCTL get_param *.MGS*.exports.*.export"
do_facet mgs "$LCTL get_param -n *.MGS*.exports.'$nid'.uuid 2>/dev/null|
grep -q -" && error "export on MGS should be empty"
do_nodes $tgts "$LCTL get_param -n *.${FSNAME}*.exports.'$nid'.uuid \
2>/dev/null | grep -q -" &&
error "export on servers should be empty"
KZPOOL=$KEEP_ZPOOL
export KEEP_ZPOOL="true"
stopall || error "stopall failed"
LOAD_MODULES_REMOTE=true unload_modules ||
error "Failed to unload modules"
# add network $net2 on all nodes
do_rpc_nodes $all load_modules || error "unable to load modules on $all"
for node in ${all//,/ }; do
do_node $node "$LNETCTL set discovery 0" ||
error "Failed to disable discovery on $node"
do_node $node "$LNETCTL lnet configure" ||
error "unable to configure lnet on node $node"
infname=inf_$(echo $node | cut -d'.' -f1 | sed s+-+_+g)
do_node $node "$LNETCTL net add --if ${!infname} --net $net2" ||
error "unable to configure NID on $net2 for node $node"
done
LOAD_MODULES_REMOTE=true load_modules || error "failed to load modules"
# update MGSNID
MGSNID=$mgsnid_orig,$mgsnid_new
stack_trap "MGSNID=$mgsnid_orig" EXIT
# add mgsnid on @$net2 to targets
for ((num = 1; num <= $MDSCOUNT; num++)); do
do_facet mds$num $TUNEFS --erase-param mgsnode \
$(mdsdevname $num)
do_facet mds$num $TUNEFS --mgsnode=$MGSNID $(mdsdevname $num)
done
for ((num = 1; num <= $OSTCOUNT; num++)); do
do_facet ost$num $TUNEFS --erase-param mgsnode \
$(ostdevname $num)
do_facet ost$num $TUNEFS --mgsnode=$MGSNID $(ostdevname $num)
done
# necessary to do writeconf in order to register
# new @$net2 nid for targets
export SK_MOUNTED=false
writeconf_all || error "writeconf failed"
nids="${addr1}@$net,${addr1}@$net2:${addr2}@$net,${addr2}@$net2"
do_facet mds1 "$TUNEFS --servicenode="$nids" $(mdsdevname 1)" ||
error "tunefs failed"
setupall server_only || error "setupall failed"
export KEEP_ZPOOL="$KZPOOL"
# on client, reconfigure LNet and turn LNet Dynamic Discovery off
$LUSTRE_RMMOD || error "$LUSTRE_RMMOD failed (1)"
load_modules || error "Failed to load modules"
$LNETCTL set discovery 0 || error "Failed to disable discovery"
$LNETCTL lnet configure ||
error "unable to configure lnet on client"
infname=inf_$(echo $(hostname -s) | sed s+-+_+g)
$LNETCTL net add --if ${!infname} --net $net2 ||
error "unable to configure NID on $net2 on client (1)"
# mount client with -o network=$net2 option
mount_client $MOUNT ${MOUNT_OPTS},network=$net2 ||
error "unable to remount client"
# check export on MGS
do_facet mgs "$LCTL get_param *.MGS*.exports.*.export"
do_facet mgs "$LCTL get_param -n *.MGS*.exports.'$nid'.uuid 2>/dev/null|
grep -" &&
error "export for $nid on MGS should not exist"
do_facet mgs "$LCTL get_param -n *.MGS*.exports.'$nid2'.uuid"|grep - ||
error "export for $nid2 on MGS should exist"
# check {mdc,osc} imports
$LCTL get_param mdc.${FSNAME}-*.import | grep current_connection |
grep $net2 ||
error "import for mdc should use ${addr1}@$net2"
$LCTL get_param osc.${FSNAME}-*.import | grep current_connection |
grep $net2 ||
error "import for osc should use ${addr1}@$net2"
# no NIDs on other networks should be listed
$LCTL get_param mdc.${FSNAME}-*.import | grep failover_nids |
grep -w ".*@$net" &&
error "MDC import shouldn't have failnids at @$net"
# failover NIDs on net999 should be listed
$LCTL get_param mdc.${FSNAME}-*.import | grep failover_nids |
grep ${addr2}@$net2 ||
error "MDC import should have failnid ${addr2}@$net2"
# unmount client
zconf_umount $HOSTNAME $MOUNT || error "unable to umount client"
do_facet mgs "$LCTL set_param mgs.MGS.exports.clear=clear"
do_nodes $tgts "$LCTL set_param *.${FSNAME}*.exports.clear=clear"
wait_update_facet_cond mgs \
"$LCTL get_param -N mgs.MGS.exports.* | grep $nid2 |
cut -d'.' -f4-" '!=' $nid2
for node in ${tgts//,/ }; do
wait_update_cond $node \
"$LCTL get_param -N *.${FSNAME}*.exports.* | grep $nid2|
cut -d'.' -f4-" '!=' $nid2
done
do_facet mgs "$LCTL get_param *.MGS*.exports.*.export"
# on client, configure LNet and turn LNet Dynamic Discovery on (default)
$LUSTRE_RMMOD || error "$LUSTRE_RMMOD failed (2)"
load_modules || error "Failed to load modules"
$LNETCTL lnet configure || error "unable to configure lnet on client"
infname=inf_$(echo $(hostname -s) | sed s+-+_+g)
$LNETCTL net add --if ${!infname} --net $net2 ||
error "unable to configure NID on $net2 on client (2)"
# mount client with -o network=$net2 option:
# should fail because of LNet Dynamic Discovery
mount_client $MOUNT ${MOUNT_OPTS},network=$net2 &&
error "client mount with '-o network' option should be refused"
# remount with '-o network' server side option
(( $MDS1_VERSION >= $(version_code 2.16.51) )) || return 0
KZPOOL=$KEEP_ZPOOL
export KEEP_ZPOOL="true"
stopall || error "stopall failed"
mountmgs
for ((num = 1; num <= $MDSCOUNT; num++)); do
start mds$num $(mdsdevname $num) $MDS_MOUNT_OPTS,network=$net2
done
for ((num = 1; num <= $OSTCOUNT; num++)); do
start ost$num $(ostdevname $num) $OST_MOUNT_OPTS,network=$net2
done
export KEEP_ZPOOL="$KZPOOL"
sleep 5
# check exports on servers are empty for $net
do_facet mgs "$LCTL get_param mgs.MGS.exports.*.export"
wait_update_facet_cond mgs \
"$LCTL get_param -N mgs.MGS.exports.*.export | \
grep ${net}.export | cut -d'@' -f2-" '!=' ${net}.export
do_nodes $tgts "$LCTL get_param *.${FSNAME}*.exports.*.export"
for node in ${tgts//,/ }; do
wait_update_cond $node \
"$LCTL get_param -N *.${FSNAME}*.exports.*.export | \
grep ${net}.export | cut -d'@' -f2-" '!=' ${net}.export
done
return 0
}
run_test 31 "client mount option '-o network'"
cleanup_32() {
# umount client
zconf_umount_clients ${clients_arr[0]} $MOUNT
# disable sk flavor enforcement on MGS
set_rule _mgs any any null
# stop gss daemon on MGS
send_sigint $mgs_HOST lsvcgssd
# re-start gss daemon on MDS if necessary
if combined_mgs_mds ; then
start_gss_daemons $mds_HOST $LSVCGSSD "-vvv -s -m -o -z"
fi
# restore MGS NIDs in key on MGS
do_nodes $mgs_HOST "$LGSS_SK -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on MGS (3)"
# load modified key file on MGS
do_nodes $mgs_HOST "$LGSS_SK -l $SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not load keyfile on MGS (3)"
# restore MGS NIDs in key on client
do_nodes ${clients_arr[0]} "$LGSS_SK -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on client (3)"
# re-mount client
MOUNT_OPTS=$(add_sk_mntflag $MOUNT_OPTS)
mountcli
restore_to_default_flavor
}
test_32() {
local mgsnid2=$(host_nids_address $ost1_HOST $NETTYPE)@${MGSNID#*@}
local mgsorig=$MGSNID
if ! $SHARED_KEY; then
skip "need shared key feature for this test"
fi
stack_trap cleanup_32 EXIT
# restore to default null flavor
save_flvr=$SK_FLAVOR
SK_FLAVOR=null
restore_to_default_flavor || error "cannot set null flavor"
SK_FLAVOR=$save_flvr
# umount client
if [ "$MOUNT_2" ] && $(grep -q $MOUNT2' ' /proc/mounts); then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
if $(grep -q $MOUNT' ' /proc/mounts); then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# kill daemon on MGS to start afresh
send_sigint $mgs_HOST lsvcgssd
# start gss daemon on MGS
if combined_mgs_mds ; then
start_gss_daemons $mgs_HOST $LSVCGSSD "-vvv -s -g -m -o -z"
else
start_gss_daemons $mgs_HOST $LSVCGSSD "-vvv -s -g"
fi
# add mgs key type and MGS NIDs in key on MGS
do_nodes $mgs_HOST "$LGSS_SK -t mgs,server -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on MGS (1)"
# load modified key file on MGS
do_nodes $mgs_HOST "$LGSS_SK -l $SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not load keyfile on MGS (1)"
# add MGS NIDs in key on client
do_nodes ${clients_arr[0]} "$LGSS_SK -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on client (1)"
# set perms for per-nodemap keys else permission denied
do_nodes $(all_nodes) \
"keyctl show | grep lustre | cut -c1-11 |
sed -e 's/ //g;' | xargs -IX keyctl setperm X 0x3f3f3f3f"
# re-mount client with mgssec=skn
save_opts=$MOUNT_OPTS
stack_trap "MOUNT_OPTS=$save_opts" EXIT
if [ -z "$MOUNT_OPTS" ]; then
MOUNT_OPTS="-o mgssec=skn"
else
MOUNT_OPTS="$MOUNT_OPTS,mgssec=skn"
fi
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "mount ${clients_arr[0]} with mgssec=skn failed"
MOUNT_OPTS=$save_opts
# umount client
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "umount ${clients_arr[0]} failed"
# enforce ska flavor on MGS
set_rule _mgs any any ska
# re-mount client without mgssec
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS &&
error "mount ${clients_arr[0]} without mgssec should fail"
# re-mount client with mgssec=skn
save_opts=$MOUNT_OPTS
if [ -z "$MOUNT_OPTS" ]; then
MOUNT_OPTS="-o mgssec=skn"
else
MOUNT_OPTS="$MOUNT_OPTS,mgssec=skn"
fi
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS &&
error "mount ${clients_arr[0]} with mgssec=skn should fail"
MOUNT_OPTS=$save_opts
# re-mount client with mgssec=ska
save_opts=$MOUNT_OPTS
if [ -z "$MOUNT_OPTS" ]; then
MOUNT_OPTS="-o mgssec=ska"
else
MOUNT_OPTS="$MOUNT_OPTS,mgssec=ska"
fi
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "mount ${clients_arr[0]} with mgssec=ska failed"
MGSNID=$mgsnid2:$mgsorig
stack_trap "MGSNID=$mgsorig" EXIT
# umount client
zconf_umount_clients ${clients_arr[0]} $MOUNT ||
error "umount ${clients_arr[0]} failed"
# add MGS NIDs in key on MGS
do_nodes $mgs_HOST "$LGSS_SK -g ${MGSNID//:/,} -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on MGS (2)"
# load modified key file on MGS
do_nodes $mgs_HOST "$LGSS_SK -l $SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not load keyfile on MGS (2)"
# add MGS NIDs in key on client
do_nodes ${clients_arr[0]} "$LGSS_SK -g ${MGSNID//:/,} -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on client (2)"
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "mount ${clients_arr[0]} with alternate mgsnid failed"
}
run_test 32 "check for mgssec"
cleanup_33() {
# disable sk flavor enforcement
set_rule $FSNAME any cli2mdt null
wait_flavor cli2mdt null
# umount client
zconf_umount_clients ${clients_arr[0]} $MOUNT
# stop gss daemon on MGS
send_sigint $mgs_HOST lsvcgssd
# re-start gss daemon on MDS if necessary
if combined_mgs_mds ; then
start_gss_daemons $mds_HOST $LSVCGSSD "-vvv -s -m -o -z"
fi
# re-mount client
MOUNT_OPTS=$(add_sk_mntflag $MOUNT_OPTS)
mountcli
restore_to_default_flavor
}
test_33() {
if ! $SHARED_KEY; then
skip "need shared key feature for this test"
fi
stack_trap cleanup_33 EXIT
# restore to default null flavor
save_flvr=$SK_FLAVOR
SK_FLAVOR=null
restore_to_default_flavor || error "cannot set null flavor"
SK_FLAVOR=$save_flvr
# umount client
if [ "$MOUNT_2" ] && $(grep -q $MOUNT2' ' /proc/mounts); then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
if $(grep -q $MOUNT' ' /proc/mounts); then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# kill daemon on MGS to start afresh
send_sigint $mgs_HOST lsvcgssd
# start gss daemon on MGS
if combined_mgs_mds ; then
start_gss_daemons $mgs_HOST $LSVCGSSD "-vvv -s -g -m -o -z"
else
start_gss_daemons $mgs_HOST $LSVCGSSD "-vvv -s -g"
fi
# add mgs key type and MGS NIDs in key on MGS
do_nodes $mgs_HOST "$LGSS_SK -t mgs,server -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on MGS"
# load modified key file on MGS
do_nodes $mgs_HOST "$LGSS_SK -l $SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not load keyfile on MGS"
# add MGS NIDs in key on client
do_nodes ${clients_arr[0]} "$LGSS_SK -g $MGSNID -m \
$SK_PATH/$FSNAME.key >/dev/null 2>&1" ||
error "could not modify keyfile on MGS"
# set perms for per-nodemap keys else permission denied
do_nodes $(all_nodes) \
"keyctl show | grep lustre | cut -c1-11 |
sed -e 's/ //g;' | xargs -IX keyctl setperm X 0x3f3f3f3f"
# re-mount client with mgssec=skn
save_opts=$MOUNT_OPTS
if [ -z "$MOUNT_OPTS" ]; then
MOUNT_OPTS="-o mgssec=skn"
else
MOUNT_OPTS="$MOUNT_OPTS,mgssec=skn"
fi
zconf_mount_clients ${clients_arr[0]} $MOUNT $MOUNT_OPTS ||
error "mount ${clients_arr[0]} with mgssec=skn failed"
MOUNT_OPTS=$save_opts
# enforce ska flavor for cli2mdt
set_rule $FSNAME any cli2mdt ska
wait_flavor cli2mdt ska
# check error message
$LCTL dk | grep "faked source" &&
error "MGS connection srpc flags incorrect"
exit 0
}
run_test 33 "correct srpc flags for MGS connection"
cleanup_34_deny() {
# restore deny_unknown
do_facet mgs $LCTL nodemap_modify --name default \
--property deny_unknown --value $denydefault
if [ $? -ne 0 ]; then
error_noexit "cannot reset deny_unknown on default nodemap"
return
fi
wait_nm_sync default deny_unknown
}
test_34() {
local denynew
local activedefault
[ $MGS_VERSION -lt $(version_code 2.12.51) ] &&
skip "deny_unknown on default nm not supported before 2.12.51"
activedefault=$(do_facet mgs $LCTL get_param -n nodemap.active)
if [[ "$activedefault" != "1" ]]; then
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
stack_trap cleanup_active EXIT
fi
denydefault=$(do_facet mgs $LCTL get_param -n \
nodemap.default.deny_unknown)
[ -z "$denydefault" ] &&
error "cannot get deny_unknown on default nodemap"
if [ "$denydefault" -eq 0 ]; then
denynew=1;
else
denynew=0;
fi
do_facet mgs $LCTL nodemap_modify --name default \
--property deny_unknown --value $denynew ||
error "cannot set deny_unknown on default nodemap"
[ "$(do_facet mgs $LCTL get_param -n nodemap.default.deny_unknown)" \
-eq $denynew ] ||
error "setting deny_unknown on default nodemap did not work"
stack_trap cleanup_34_deny EXIT
wait_nm_sync default deny_unknown
}
run_test 34 "deny_unknown on default nodemap"
test_35() {
(( $MDS1_VERSION >= $(version_code 2.13.50) )) ||
skip "Need MDS >= 2.13.50"
# activate changelogs
changelog_register || error "changelog_register failed"
local cl_user="${CL_USERS[$SINGLEMDS]%% *}"
changelog_users $SINGLEMDS | grep -q $cl_user ||
error "User $cl_user not found in changelog_users"
changelog_chmask ALL
# do some IOs
mkdir $DIR/$tdir || error "failed to mkdir $tdir"
touch $DIR/$tdir/$tfile || error "failed to touch $tfile"
# access changelogs with root
changelog_dump || error "failed to dump changelogs"
changelog_clear 0 || error "failed to clear changelogs"
# put clients in non-admin nodemap
nodemap_test_setup
stack_trap nodemap_test_cleanup EXIT
for i in $(seq 0 $((num_clients-1))); do
do_facet mgs $LCTL nodemap_modify --name c${i} \
--property admin --value 0
done
wait_nm_sync c$((num_clients - 1)) admin_nodemap
# access with mapped root
changelog_dump && error "dump changelogs should have failed"
changelog_clear 0 && error "clear changelogs should have failed"
exit 0
}
run_test 35 "Check permissions when accessing changelogs"
setup_dummy_key() {
local mode='\x00\x00\x00\x00'
local raw="$(printf ""\\\\x%02x"" {0..63})"
local size
local key
[[ $(lscpu) =~ Byte\ Order.*Little ]] && size='\x40\x00\x00\x00' ||
size='\x00\x00\x00\x40'
key="${mode}${raw}${size}"
echo -n -e "${key}" | keyctl padd logon fscrypt:4242424242424242 @s
}
insert_enc_key() {
cancel_lru_locks
sync ; echo 3 > /proc/sys/vm/drop_caches
setup_dummy_key
}
remove_enc_key() {
local dummy_key
$LCTL set_param -n ldlm.namespaces.*.lru_size=clear || true
sync ; echo 3 > /proc/sys/vm/drop_caches
dummy_key=$(keyctl show | awk '$7 ~ "^fscrypt:" {print $1}')
if [ -n "$dummy_key" ]; then
keyctl revoke $dummy_key
keyctl reap
fi
}
remount_client_normally() {
local ldlmcount=$((MDSCOUNT+OSTCOUNT))
# remount client without dummy encryption key
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
mount_client $MOUNT ${MOUNT_OPTS} ||
error "remount failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} ||
error "remount failed"
ldlmcount=$((ldlmcount*2))
fi
# add 1 for the MGS connection
((ldlmcount++))
wait_update_facet --verbose client \
"$LCTL get_param -n ldlm.namespaces.*.lru_size | wc -l" \
$ldlmcount 120 ||
error "leftover ldlms"
remove_enc_key
wait_ssk
}
remount_client_dummykey() {
insert_enc_key
# remount client with dummy encryption key
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
mount_client $MOUNT ${MOUNT_OPTS},test_dummy_encryption ||
error "remount failed"
wait_ssk
}
setup_for_enc_tests() {
# remount client with test_dummy_encryption option
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
mount_client $MOUNT ${MOUNT_OPTS},test_dummy_encryption ||
error "mount with '-o test_dummy_encryption' failed"
wait_ssk
# this directory will be encrypted, because of dummy mode
mkdir $DIR/$tdir
}
cleanup_for_enc_tests() {
rm -rf $DIR/$tdir $*
remount_client_normally
}
cleanup_nodemap_after_enc_tests() {
umount_client $MOUNT || true
if (( MGS_VERSION >= $(version_code 2.13.55) )); then
do_facet mgs $LCTL nodemap_modify --name default \
--property forbid_encryption --value 0
if (( MGS_VERSION >= $(version_code 2.15.51) )); then
do_facet mgs $LCTL nodemap_modify --name default \
--property readonly_mount --value 0
fi
fi
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0
do_facet mgs $LCTL nodemap_activate 0
if (( MGS_VERSION >= $(version_code 2.13.55) )); then
wait_nm_sync default forbid_encryption '' inactive
if (( MGS_VERSION >= $(version_code 2.15.51) )); then
wait_nm_sync default readonly_mount '' inactive
fi
fi
wait_nm_sync active
mount_client $MOUNT ${MOUNT_OPTS} || error "re-mount failed"
wait_ssk
}
test_36() {
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
# first make sure it is possible to enable encryption
# when nodemap is not active
setup_for_enc_tests
rmdir $DIR/$tdir
umount_client $MOUNT || error "umount $MOUNT failed (1)"
# then activate nodemap, and retry
# should succeed as encryption is not forbidden on default nodemap
# by default
stack_trap cleanup_nodemap_after_enc_tests EXIT
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
forbid=$(do_facet mgs lctl get_param -n nodemap.default.forbid_encryption)
[ $forbid -eq 0 ] || error "wrong default value for forbid_encryption"
mount_client $MOUNT ${MOUNT_OPTS},test_dummy_encryption ||
error "mount '-o test_dummy_encryption' failed with default"
umount_client $MOUNT || error "umount $MOUNT failed (2)"
# then forbid encryption, and retry
do_facet mgs $LCTL nodemap_modify --name default \
--property forbid_encryption --value 1
wait_nm_sync default forbid_encryption
mount_client $MOUNT ${MOUNT_OPTS},test_dummy_encryption &&
error "mount '-o test_dummy_encryption' should have failed"
return 0
}
run_test 36 "control if clients can use encryption"
test_37() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local objdump=$TMP/objdump
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[ "$ost1_FSTYPE" = ldiskfs ] || skip "ldiskfs only test (using debugfs)"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# write a few bytes in file
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=4 count=1 conv=fsync
do_facet ost1 "sync; sync"
# check that content on ost is encrypted
local fids=($($LFS getstripe $testfile | grep 0x))
local fid="${fids[3]}:${fids[2]}:0"
local objpath=$(ost_fid2_objpath ost1 $fid)
do_facet ost1 "$DEBUGFS -c -R 'cat $objpath' $(ostdevname 1)" > $objdump
cmp -s $objdump $tmpfile &&
error "file $testfile is not encrypted on ost"
# check that in-memory representation of file is correct
cmp -bl ${tmpfile} ${testfile} ||
error "file $testfile is corrupted in memory"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl ${tmpfile} ${testfile} ||
error "file $testfile is corrupted on server"
rm -f $tmpfile $objdump
}
run_test 37 "simple encrypted file"
test_38() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local blksz
local filesz
local bsize
local pagesz=$(getconf PAGE_SIZE)
[[ $(facet_fstype ost1) == zfs ]] && skip "skip ZFS backend"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# get block size on ost
blksz=$($LCTL get_param osc.$FSNAME*.import |
awk '/grant_block_size:/ { print $2; exit; }')
# write a few bytes in file at offset $blksz
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$blksz \
oflag=seek_bytes conv=fsync
blksz=$(($blksz > $pagesz ? $blksz : $pagesz))
# check that in-memory representation of file is correct
bsize=$(stat --format=%B $testfile)
filesz=$(stat --format=%b $testfile)
filesz=$((filesz*bsize))
[ $filesz -le $blksz ] ||
error "file $testfile is $filesz long in memory"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
bsize=$(stat --format=%B $testfile)
filesz=$(stat --format=%b $testfile)
filesz=$((filesz*bsize))
[ $filesz -le $blksz ] ||
error "file $testfile is $filesz long on server"
rm -f $tmpfile
}
run_test 38 "encrypted file with hole"
test_39() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# write a few bytes in file
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=4 count=1 conv=fsync
# write a few more bytes in the same page
dd if=$tmpfile of=$testfile bs=4 count=1 seek=1024 oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile bs=4 count=1 seek=1024 oflag=seek_bytes \
conv=fsync,notrunc
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server"
rm -f $tmpfile
}
run_test 39 "rewrite data in already encrypted page"
test_40() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local tmpfile2=$TMP/abc2
local seek
local filesz
#define LUSTRE_ENCRYPTION_UNIT_SIZE (1 << 12)
local UNIT_SIZE=$((1 << 12))
local scrambledfile
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $OSTCOUNT -lt 2 ]] && skip_env "needs >= 2 OSTs"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# write a few bytes in file
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=4 count=1 conv=fsync
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory (1)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server (1)"
# write a few other bytes in same page
dd if=$tmpfile of=$testfile bs=4 count=1 seek=256 oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile bs=4 count=1 seek=256 oflag=seek_bytes \
conv=fsync,notrunc
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory (2)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server (2)"
rm -f $testfile $tmpfile
cancel_lru_locks osc ; cancel_lru_locks mdc
# write a few bytes in file, at end of first page
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
seek=$(getconf PAGESIZE)
seek=$((seek - 4))
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# write a few other bytes at beginning of first page
dd if=$tmpfile of=$testfile bs=4 count=1 conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory (3)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server (3)"
rm -f $testfile $tmpfile
cancel_lru_locks osc ; cancel_lru_locks mdc
# write a few bytes in file, at beginning of second page
echo "abc" > $tmpfile
$LFS setstripe -c1 -i0 $testfile
seek=$(getconf PAGESIZE)
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# write a few other bytes at end of first page
seek=$((seek - 4))
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# check that in-memory representation of file is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted in memory (4)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted on server (4)"
rm -f $testfile $tmpfile $tmpfile2
cancel_lru_locks osc ; cancel_lru_locks mdc
# write a few bytes in file, at beginning of first stripe
echo "abc" > $tmpfile
$LFS setstripe -S 256k -c2 $testfile
dd if=$tmpfile of=$testfile bs=4 count=1 conv=fsync,notrunc
# write a few other bytes, at beginning of second stripe
dd if=$tmpfile of=$testfile bs=4 count=1 seek=262144 oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile of=$tmpfile bs=4 count=1 seek=262144 oflag=seek_bytes \
conv=fsync,notrunc
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory (5)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server (5)"
filesz=$(stat --format=%s $testfile)
filesz=$(((filesz+UNIT_SIZE-1)/UNIT_SIZE * UNIT_SIZE))
# remount without dummy encryption key
remount_client_normally
scrambledfile=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type f)
[ $(stat --format=%s $scrambledfile) -eq $filesz ] ||
error "file size without key should be rounded up"
rm -f $tmpfile
}
run_test 40 "exercise size of encrypted file"
test_41() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local tmpfile2=$TMP/abc2
local seek
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
echo "abc" > $tmpfile
seek=$(getconf PAGESIZE)
seek=$((seek - 204))
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync
seek=$(getconf PAGESIZE)
seek=$((seek + 1092))
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# write a few bytes in file
$LFS setstripe -c1 -i0 -S 256k $testfile
seek=$(getconf PAGESIZE)
seek=$((seek - 204))
#define OBD_FAIL_OST_WR_ATTR_DELAY 0x250
do_facet ost1 "$LCTL set_param fail_loc=0x250 fail_val=15"
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync &
sleep 5
# write a few other bytes, at a different offset
seek=$(getconf PAGESIZE)
seek=$((seek + 1092))
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc &
wait
do_facet ost1 "$LCTL set_param fail_loc=0x0"
# check that in-memory representation of file is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted in memory (1)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted on server (1)"
rm -f $tmpfile $tmpfile2
}
run_test 41 "test race on encrypted file size (1)"
test_42() {
local testfile=$DIR/$tdir/$tfile
local testfile2=$DIR2/$tdir/$tfile
local tmpfile=$TMP/abc
local tmpfile2=$TMP/abc2
local pagesz=$(getconf PAGESIZE)
local seek
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
mount_client $MOUNT2 ${MOUNT_OPTS},test_dummy_encryption ||
error "mount2 with '-o test_dummy_encryption' failed"
# create file by writting one whole page
$LFS setstripe -c1 -i0 -S 256k $testfile
dd if=/dev/zero of=$testfile bs=$pagesz count=1 conv=fsync
# read file from 2nd mount point
cat $testfile2 > /dev/null
echo "abc" > $tmpfile
dd if=/dev/zero of=$tmpfile2 bs=$pagesz count=1 conv=fsync
seek=$((2*pagesz - 204))
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
seek=$((2*pagesz + 1092))
dd if=$tmpfile of=$tmpfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
# write a few bytes in file from 1st mount point
seek=$((2*pagesz - 204))
#define OBD_FAIL_OST_WR_ATTR_DELAY 0x250
do_facet ost1 "$LCTL set_param fail_loc=0x250 fail_val=15"
dd if=$tmpfile of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc &
sleep 5
# write a few other bytes, at a different offset from 2nd mount point
seek=$((2*pagesz + 1092))
dd if=$tmpfile of=$testfile2 bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc &
wait
do_facet ost1 "$LCTL set_param fail_loc=0x0"
# check that in-memory representation of file is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted in memory (1)"
# check that in-memory representation of file is correct
cmp -bl $tmpfile2 $testfile2 ||
error "file $testfile is corrupted in memory (2)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile2 $testfile ||
error "file $testfile is corrupted on server (1)"
rm -f $tmpfile $tmpfile2
}
run_test 42 "test race on encrypted file size (2)"
test_43() {
local testfile=$DIR/$tdir/$tfile
local testfile2=$DIR2/$tdir/$tfile
local tmpfile=$TMP/abc
local tmpfile2=$TMP/abc2
local resfile=$TMP/res
local pagesz=$(getconf PAGESIZE)
local seek
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
mount_client $MOUNT2 ${MOUNT_OPTS},test_dummy_encryption ||
error "mount2 with '-o test_dummy_encryption' failed"
# create file
tr '\0' '1' < /dev/zero |
dd of=$tmpfile bs=1 count=$pagesz conv=fsync
$LFS setstripe -c1 -i0 -S 256k $testfile
cp $tmpfile $testfile
# read file from 2nd mount point
cat $testfile2 > /dev/null
# write a few bytes in file from 1st mount point
echo "abc" > $tmpfile2
seek=$((2*pagesz - 204))
#define OBD_FAIL_OST_WR_ATTR_DELAY 0x250
do_facet ost1 "$LCTL set_param fail_loc=0x250 fail_val=15"
dd if=$tmpfile2 of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc &
sleep 5
# read file from 2nd mount point
dd if=$testfile2 of=$resfile bs=$pagesz count=1 conv=fsync,notrunc
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted in memory (1)"
wait
do_facet ost1 "$LCTL set_param fail_loc=0x0"
# check that in-memory representation of file is correct
dd if=$tmpfile2 of=$tmpfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
cmp -bl $tmpfile $testfile2 ||
error "file $testfile is corrupted in memory (2)"
cancel_lru_locks osc ; cancel_lru_locks mdc
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server (1)"
rm -f $tmpfile $tmpfile2
}
run_test 43 "test race on encrypted file size (3)"
test_44() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local resfile=$TMP/resfile
local pagesz=$(getconf PAGESIZE)
local respage
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
which vmtouch || skip "This test needs vmtouch utility"
# Direct I/O is now supported on encrypted files.
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
$LFS setstripe -c1 -i0 $testfile
dd if=/dev/urandom of=$tmpfile bs=$pagesz count=2 conv=fsync
dd if=$tmpfile of=$testfile bs=$pagesz count=2 oflag=direct ||
error "could not write to file with O_DIRECT (1)"
respage=$(vmtouch $testfile | awk '/Resident Pages:/ {print $3}')
[ "$respage" == "0/2" ] ||
error "write to enc file fell back to buffered IO"
cancel_lru_locks
dd if=$testfile of=$resfile bs=$pagesz count=2 iflag=direct ||
error "could not read from file with O_DIRECT (1)"
respage=$(vmtouch $testfile | awk '/Resident Pages:/ {print $3}')
[ "$respage" == "0/2" ] ||
error "read from enc file fell back to buffered IO"
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted (1)"
rm -f $resfile
$TRUNCATE $tmpfile $pagesz
dd if=$tmpfile of=$testfile bs=$pagesz count=1 seek=13 oflag=direct ||
error "could not write to file with O_DIRECT (2)"
cancel_lru_locks
dd if=$testfile of=$resfile bs=$pagesz count=1 skip=13 iflag=direct ||
error "could not read from file with O_DIRECT (2)"
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted (2)"
rm -f $testfile $resfile
$LFS setstripe -c1 -i0 $testfile
$TRUNCATE $tmpfile $((pagesz/2 - 5))
cp $tmpfile $testfile
cancel_lru_locks
dd if=$testfile of=$resfile bs=$pagesz count=1 iflag=direct ||
error "could not read from file with O_DIRECT (3)"
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted (3)"
rm -f $tmpfile $resfile $testfile
if [ $OSTCOUNT -ge 2 ]; then
dd if=/dev/urandom of=$tmpfile bs=$pagesz count=1 conv=fsync
$LFS setstripe -S 256k -c2 $testfile
# write in file, at beginning of first stripe, buffered IO
dd if=$tmpfile of=$testfile bs=$pagesz count=1 \
conv=fsync,notrunc
# write at beginning of second stripe, direct IO
dd if=$tmpfile of=$testfile bs=$pagesz count=1 seek=256k \
oflag=seek_bytes,direct conv=fsync,notrunc
cancel_lru_locks
# read at beginning of first stripe, direct IO
dd if=$testfile of=$resfile bs=$pagesz count=1 \
iflag=direct conv=fsync
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted (4)"
# read at beginning of second stripe, buffered IO
dd if=$testfile of=$resfile bs=$pagesz count=1 skip=256k \
iflag=skip_bytes conv=fsync
cmp -bl $tmpfile $resfile ||
error "file $testfile is corrupted (5)"
rm -f $tmpfile $resfile
fi
}
run_test 44 "encrypted file access semantics: direct IO"
test_45() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/junk
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
$LFS setstripe -c1 -i0 $testfile
dd if=/dev/zero of=$testfile bs=512K count=1
$MULTIOP $testfile OSMRUc || error "$MULTIOP $testfile failed (1)"
$MULTIOP $testfile OSMWUc || error "$MULTIOP $testfile failed (2)"
dd if=/dev/zero of=$tmpfile bs=512K count=1
$MULTIOP $tmpfile OSMWUc || error "$MULTIOP $tmpfile failed"
$MMAP_CAT $tmpfile > ${tmpfile}2
cancel_lru_locks
$MULTIOP $testfile OSMRUc
$MMAP_CAT $testfile > ${testfile}2
cmp -bl ${tmpfile}2 ${testfile}2 ||
error "file $testfile is corrupted"
rm -f $tmpfile ${tmpfile}2
}
run_test 45 "encrypted file access semantics: MMAP"
test_46() {
local testdir=$DIR/$tdir/mydir
local testfile=$testdir/myfile
local testdir2=$DIR/$tdir/mydirwithaveryverylongnametotestcodebehaviour0
local testfile2=$testdir/myfilewithaveryverylongnametotestcodebehaviour0
# testdir3, testfile3, testhl3 and testsl3 names are 255 bytes long
local testdir3=$testdir2/dir_abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz012345678
local testfile3=$testdir2/file_abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz01234567
local testhl3=$testdir2/hl_abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789
local testsl3=$testdir2/sl_abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789abcdefghijklmnopqrstuvwxyz0123456789
local lsfile=$TMP/lsfile
local scrambleddir
local scrambledfile
local inum
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
touch $DIR/$tdir/$tfile
mkdir $testdir
echo test > $testfile
echo othertest > $testfile2
if [[ $MDSCOUNT -gt 1 ]]; then
$LFS setdirstripe -c1 -i1 $testdir2
else
mkdir $testdir2
fi
inum=$(stat -c %i $testdir2)
if [ "$mds1_FSTYPE" = ldiskfs ]; then
# For now, restrict this part of the test to ldiskfs backend,
# as osd-zfs does not support 255 byte-long encrypted names.
mkdir $testdir3 || error "cannot mkdir $testdir3"
touch $testfile3 || error "cannot touch $testfile3"
ln $testfile3 $testhl3 || error "cannot ln $testhl3"
ln -s $testfile3 $testsl3 || error "cannot ln $testsl3"
fi
sync ; echo 3 > /proc/sys/vm/drop_caches
# remount without dummy encryption key
remount_client_normally
# this is $testdir2
scrambleddir=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -inum $inum)
stat $scrambleddir || error "stat $scrambleddir failed"
if [ "$mds1_FSTYPE" = ldiskfs ]; then
stat $scrambleddir/* || error "cannot stat in $scrambleddir"
rm -rf $scrambleddir/* || error "cannot clean in $scrambleddir"
fi
rmdir $scrambleddir || error "rmdir $scrambleddir failed"
scrambleddir=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type d)
ls -1 $scrambleddir > $lsfile || error "ls $testdir failed (1)"
scrambledfile=$scrambleddir/$(head -n 1 $lsfile)
stat $scrambledfile || error "stat $scrambledfile failed (1)"
rm -f $lsfile
cat $scrambledfile && error "cat $scrambledfile should have failed (1)"
rm -f $scrambledfile || error "rm $scrambledfile failed (1)"
ls -1 $scrambleddir > $lsfile || error "ls $testdir failed (2)"
scrambledfile=$scrambleddir/$(head -n 1 $lsfile)
stat $scrambledfile || error "stat $scrambledfile failed (2)"
rm -f $lsfile
cat $scrambledfile && error "cat $scrambledfile should have failed (2)"
touch $scrambleddir/otherfile &&
error "touch otherfile should have failed"
ls $scrambleddir/otherfile && error "otherfile should not exist"
mkdir $scrambleddir/otherdir &&
error "mkdir otherdir should have failed"
ls -d $scrambleddir/otherdir && error "otherdir should not exist"
ls -R $DIR
rm -f $scrambledfile || error "rm $scrambledfile failed (2)"
rmdir $scrambleddir || error "rmdir $scrambleddir failed"
ls -R $DIR
}
run_test 46 "encrypted file access semantics without key"
test_47() {
local testfile=$DIR/$tdir/$tfile
local testfile2=$DIR/$tdir/${tfile}.2
local tmpfile=$DIR/junk
local name_enc=1
local scrambleddir
local scrambledfile
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
$LCTL get_param mdc.*.connect_flags | grep -q name_encryption ||
name_enc=0
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
dd if=/dev/urandom of=$tmpfile bs=512K count=1
mrename $tmpfile $testfile &&
error "rename from unencrypted to encrypted dir should fail"
ln $tmpfile $testfile &&
error "link from encrypted to unencrypted dir should fail"
cp $tmpfile $testfile ||
error "cp from unencrypted to encrypted dir should succeed"
rm -f $tmpfile
mrename $testfile $testfile2 ||
error "rename from within encrypted dir should succeed"
ln $testfile2 $testfile ||
error "link from within encrypted dir should succeed"
cmp -bl $testfile2 $testfile ||
error "cannot read from hard link (1.1)"
echo a >> $testfile || error "cannot write to hard link (1)"
cancel_lru_locks
cmp -bl $testfile2 $testfile ||
error "cannot read from hard link (1.2)"
rm -f $testfile
ln $testfile2 $tmpfile ||
error "link from unencrypted to encrypted dir should succeed"
cancel_lru_locks
cmp -bl $testfile2 $tmpfile ||
error "cannot read from hard link (2.1)"
echo a >> $tmpfile || error "cannot write to hard link (2)"
cancel_lru_locks
cmp -bl $testfile2 $tmpfile ||
error "cannot read from hard link (2.2)"
rm -f $tmpfile
if [ $name_enc -eq 1 ]; then
# check we are limited in the number of hard links
# we can create for encrypted files, to what can fit into LinkEA
for i in $(seq 1 160); do
ln $testfile2 ${testfile}_$i || break
done
[ $i -lt 160 ] || error "hard link $i should fail"
rm -f ${testfile}_*
fi
mrename $testfile2 $tmpfile &&
error "rename from encrypted to unencrypted dir should fail"
rm -f $testfile2
dd if=/dev/urandom of=$tmpfile bs=512K count=1
dd if=/dev/urandom of=$testfile bs=512K count=1
mkdir $DIR/$tdir/mydir
ln -s $testfile ${testfile}.sym ||
error "symlink from within encrypted dir should succeed"
cancel_lru_locks
cmp -bl $testfile ${testfile}.sym ||
error "cannot read from sym link (1.1)"
echo a >> ${testfile}.sym || error "cannot write to sym link (1)"
cancel_lru_locks
cmp -bl $testfile ${testfile}.sym ||
error "cannot read from sym link (1.2)"
[ $(stat -c %s ${testfile}.sym) -eq ${#testfile} ] ||
error "wrong symlink size (1)"
ln -s $tmpfile ${testfile}.sl ||
error "symlink from encrypted to unencrypted dir should succeed"
cancel_lru_locks
cmp -bl $tmpfile ${testfile}.sl ||
error "cannot read from sym link (2.1)"
echo a >> ${testfile}.sl || error "cannot write to sym link (2)"
cancel_lru_locks
cmp -bl $tmpfile ${testfile}.sl ||
error "cannot read from sym link (2.2)"
[ $(stat -c %s ${testfile}.sl) -eq ${#tmpfile} ] ||
error "wrong symlink size (2)"
rm -f ${testfile}.sl
sync ; echo 3 > /proc/sys/vm/drop_caches
# remount without dummy encryption key
remount_client_normally
scrambleddir=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type d)
scrambledfile=$(find $DIR/$tdir/ -maxdepth 1 -type f)
scrambledlink=$(find $DIR/$tdir/ -maxdepth 1 -type l)
ln $scrambledfile $scrambleddir/linkfile &&
error "ln linkfile should have failed"
mrename $scrambledfile $DIR/onefile2 &&
error "mrename from $scrambledfile should have failed"
touch $DIR/onefile
mrename $DIR/onefile $scrambleddir/otherfile &&
error "mrename to $scrambleddir should have failed"
readlink $scrambledlink ||
error "link should be read without key"
[ $(stat -c %s $scrambledlink) -eq \
$(expr length "$(readlink $scrambledlink)") ] ||
error "wrong symlink size without key"
if [ $name_enc -eq 1 ]; then
readlink -e $scrambledlink &&
error "link should not point to anywhere useful"
fi
ln -s $scrambledfile ${scrambledfile}.sym &&
error "symlink without key should fail (1)"
ln -s $tmpfile ${scrambledfile}.sl &&
error "symlink without key should fail (2)"
rm -f $tmpfile $DIR/onefile
}
run_test 47 "encrypted file access semantics: rename/link"
test_48a() {
local save="$TMP/$TESTSUITE-$TESTNAME.parameters"
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/111
local tmpfile2=$TMP/abc
local pagesz=$(getconf PAGESIZE)
local sz
local seek
local scrambledfile
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# create file, 4 x PAGE_SIZE long
tr '\0' '1' < /dev/zero |
dd of=$tmpfile bs=1 count=4x$pagesz conv=fsync
$LFS setstripe -c1 -i0 $testfile
cp $tmpfile $testfile
echo "abc" > $tmpfile2
# decrease size: truncate to PAGE_SIZE
$TRUNCATE $tmpfile $pagesz
$TRUNCATE $testfile $pagesz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (1)"
# increase size: truncate to 2 x PAGE_SIZE
sz=$((pagesz*2))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (2)"
# write in 2nd page
seek=$((pagesz+100))
dd if=$tmpfile2 of=$tmpfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
dd if=$tmpfile2 of=$testfile bs=4 count=1 seek=$seek oflag=seek_bytes \
conv=fsync,notrunc
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (3)"
# truncate to PAGE_SIZE / 2
sz=$((pagesz/2))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (4)"
# truncate to a smaller, non-multiple of PAGE_SIZE, non-multiple of 16
sz=$((sz-7))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (5)"
# truncate to a larger, non-multiple of PAGE_SIZE, non-multiple of 16
sz=$((sz+18))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (6)"
# truncate to a larger, non-multiple of PAGE_SIZE, in a different page
sz=$((sz+pagesz+30))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
cancel_lru_locks osc ; cancel_lru_locks mdc
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (7)"
sync ; echo 3 > /proc/sys/vm/drop_caches
# remount without dummy encryption key
remount_client_normally
scrambledfile=$(find $DIR/$tdir/ -maxdepth 1 -type f)
$TRUNCATE $scrambledfile 0 &&
error "truncate $scrambledfile should have failed without key"
rm -f $tmpfile $tmpfile2
}
run_test 48a "encrypted file access semantics: truncate"
cleanup_for_enc_tests_othercli() {
local othercli=$1
# remount othercli normally
zconf_umount $othercli $MOUNT ||
error "umount $othercli $MOUNT failed"
zconf_mount $othercli $MOUNT ||
error "remount $othercli $MOUNT failed"
}
test_48b() {
local othercli
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[ "$num_clients" -ge 2 ] || skip "Need at least 2 clients"
if [ "$HOSTNAME" == ${clients_arr[0]} ]; then
othercli=${clients_arr[1]}
else
othercli=${clients_arr[0]}
fi
stack_trap cleanup_for_enc_tests EXIT
stack_trap "cleanup_for_enc_tests_othercli $othercli" EXIT
setup_for_enc_tests
zconf_umount $othercli $MOUNT ||
error "umount $othercli $MOUNT failed"
cp /bin/sleep $DIR/$tdir/
cancel_lru_locks osc ; cancel_lru_locks mdc
$DIR/$tdir/sleep 30 &
# mount and IOs must be done in the same shell session, otherwise
# encryption key in session keyring is missing
do_node $othercli "$MOUNT_CMD -o ${MOUNT_OPTS},test_dummy_encryption \
$MGSNID:/$FSNAME $MOUNT && \
$TRUNCATE $DIR/$tdir/sleep 7"
wait || error "wait error"
cmp --silent /bin/sleep $DIR/$tdir/sleep ||
error "/bin/sleep and $DIR/$tdir/sleep differ"
}
run_test 48b "encrypted file: concurrent truncate"
trace_cmd() {
local cmd="$@"
cancel_lru_locks
$LCTL set_param debug=+info
$LCTL clear
echo $cmd
eval $cmd
[ $? -eq 0 ] || error "$cmd failed"
if [ -z "$MATCHING_STRING" ]; then
$LCTL dk | grep -E "get xattr 'encryption.c'|get xattrs"
else
$LCTL dk | grep -E "$MATCHING_STRING"
fi
[ $? -ne 0 ] || error "get xattr event was triggered"
}
test_49() {
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
local dirname=$DIR/$tdir/subdir
mkdir $dirname
trace_cmd stat $dirname
trace_cmd echo a > $dirname/f1
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd stat $dirname/f1
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd cat $dirname/f1
dd if=/dev/zero of=$dirname/f1 bs=1M count=10 conv=fsync
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
MATCHING_STRING="get xattr 'encryption.c'" \
trace_cmd $TRUNCATE $dirname/f1 10240
trace_cmd $LFS setstripe -E -1 -S 4M $dirname/f2
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd $LFS migrate -E -1 -S 256K $dirname/f2
if [[ $MDSCOUNT -gt 1 ]]; then
trace_cmd $LFS setdirstripe -i 1 $dirname/d2
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd $LFS migrate -m 0 $dirname/d2
echo b > $dirname/d2/subf
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
if (( "$MDS1_VERSION" > $(version_code 2.14.54.54) )); then
# migrate a non-empty encrypted dir
trace_cmd $LFS migrate -m 1 $dirname/d2
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
[ -f $dirname/d2/subf ] || error "migrate failed (1)"
[ $(cat $dirname/d2/subf) == "b" ] ||
error "migrate failed (2)"
fi
$LFS setdirstripe -i 1 -c 1 $dirname/d3
dirname=$dirname/d3/subdir
mkdir $dirname
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd stat $dirname
trace_cmd echo c > $dirname/f1
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd stat $dirname/f1
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd cat $dirname/f1
dd if=/dev/zero of=$dirname/f1 bs=1M count=10 conv=fsync
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
MATCHING_STRING="get xattr 'encryption.c'" \
trace_cmd $TRUNCATE $dirname/f1 10240
trace_cmd $LFS setstripe -E -1 -S 4M $dirname/f2
sync ; sync ; echo 3 > /proc/sys/vm/drop_caches
trace_cmd $LFS migrate -E -1 -S 256K $dirname/f2
else
skip_noexit "2nd part needs >= 2 MDTs"
fi
}
run_test 49 "Avoid getxattr for encryption context"
test_50() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/abc
local pagesz=$(getconf PAGESIZE)
local sz
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# write small file, data on MDT only
tr '\0' '1' < /dev/zero |
dd of=$tmpfile bs=1 count=5000 conv=fsync
$LFS setstripe -E 1M -L mdt -E EOF $testfile
cp $tmpfile $testfile
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory"
remove_enc_key ; insert_enc_key
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server"
# decrease size: truncate to PAGE_SIZE
$TRUNCATE $tmpfile $pagesz
$TRUNCATE $testfile $pagesz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (1)"
# increase size: truncate to 2 x PAGE_SIZE
sz=$((pagesz*2))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (2)"
# truncate to PAGE_SIZE / 2
sz=$((pagesz/2))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (3)"
# truncate to a smaller, non-multiple of PAGE_SIZE, non-multiple of 16
sz=$((sz-7))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (4)"
# truncate to a larger, non-multiple of PAGE_SIZE, non-multiple of 16
sz=$((sz+18))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (5)"
# truncate to a larger, non-multiple of PAGE_SIZE, in a different page
sz=$((sz+pagesz+30))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (6)"
rm -f $testfile
remove_enc_key ; insert_enc_key
# write hole in file, data spread on MDT and OST
tr '\0' '2' < /dev/zero |
dd of=$tmpfile bs=1 count=1539 seek=1539074 conv=fsync,notrunc
$LFS setstripe -E 1M -L mdt -E EOF $testfile
cp --sparse=always $tmpfile $testfile
# check that in-memory representation of file is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted in memory"
remove_enc_key ; insert_enc_key
# check that file read from server is correct
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted on server"
# truncate to a smaller, non-multiple of PAGE_SIZE, non-multiple of 16,
# inside OST part of data
sz=$((1024*1024+13))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (7)"
# truncate to a smaller, non-multiple of PAGE_SIZE, non-multiple of 16,
# inside MDT part of data
sz=7
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (8)"
# truncate to a larger, non-multiple of PAGE_SIZE, non-multiple of 16,
# inside MDT part of data
sz=$((1024*1024-13))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (9)"
# truncate to a larger, non-multiple of PAGE_SIZE, non-multiple of 16,
# inside OST part of data
sz=$((1024*1024+7))
$TRUNCATE $tmpfile $sz
$TRUNCATE $testfile $sz
remove_enc_key ; insert_enc_key
cmp -bl $tmpfile $testfile ||
error "file $testfile is corrupted (10)"
rm -f $tmpfile
}
run_test 50 "DoM encrypted file"
test_51() {
(( "$MDS1_VERSION" >= $(version_code v2_13_55-38-gf05edf8e2b) )) ||
skip "Need MDS version at least 2.13.55.38"
mkdir $DIR/$tdir || error "mkdir $tdir"
local mdts=$(mdts_nodes)
local cap_param=mdt.*.enable_cap_mask
local nm_param=nodemap.default.enable_cap_mask
local val
old_cap=($(do_nodes $mdts $LCTL get_param -n $cap_param 2>/dev/null))
if [[ -n "$old_cap" ]]; then
local new_cap="+cap_chown+cap_fowner+cap_dac_override+cap_dac_read_search"
(( MDS1_VERSION >= $(version_code 2.15.63.14) )) ||
(( MDS1_VERSION < $(version_code 2.15.0) &&
MDS1_VERSION > $(version_code 2.14.0.135) )) ||
new_cap=0xf
echo "old_cap: $old_cap new_cap: $new_cap"
do_nodes $mdts $LCTL set_param $cap_param=$new_cap
stack_trap "do_nodes $mdts $LCTL set_param $cap_param=$old_cap"
fi
touch $DIR/$tdir/$tfile || error "touch $tfile as root (1)"
cp $(which chown) $DIR/$tdir || error "cp chown"
$RUNAS_CMD -u $ID0 $DIR/$tdir/chown $ID0 $DIR/$tdir/$tfile &&
error "chown $tfile should fail (1)"
setcap 'CAP_CHOWN=ep' $DIR/$tdir/chown || error "setcap CAP_CHOWN"
$RUNAS_CMD -u $ID0 $DIR/$tdir/chown $ID0 $DIR/$tdir/$tfile ||
error "chown $tfile as $ID0 (1)"
rm $DIR/$tdir/$tfile || error "rm $tfile (1)"
touch $DIR/$tdir/$tfile || error "touch $tfile as root (2)"
cp $(which touch) $DIR/$tdir || error "cp touch"
$RUNAS_CMD -u $ID0 $DIR/$tdir/touch $DIR/$tdir/$tfile &&
error "touch should fail"
setcap 'CAP_FOWNER=ep' $DIR/$tdir/touch || error "setcap CAP_FOWNER"
$RUNAS_CMD -u $ID0 $DIR/$tdir/touch $DIR/$tdir/$tfile ||
error "touch $tfile"
rm $DIR/$tdir/$tfile || error "rm $tfile (2)"
local cap
for cap in "CAP_DAC_OVERRIDE" "CAP_DAC_READ_SEARCH"; do
touch $DIR/$tdir/$tfile || error "touch $tfile as root (3)"
chmod 600 $DIR/$tdir/$tfile || error "chmod $tfile"
cp $(which cat) $DIR/$tdir || error "cp cat"
$RUNAS_CMD -u $ID0 $DIR/$tdir/cat $DIR/$tdir/$tfile &&
error "cat should fail"
setcap $cap=ep $DIR/$tdir/cat || error "setcap $cap"
$RUNAS_CMD -u $ID0 $DIR/$tdir/cat $DIR/$tdir/$tfile ||
error "cat $tfile"
rm $DIR/$tdir/$tfile || error "rm $tfile (3)"
done
if (( "$MDS1_VERSION" >= $(version_code 2.16.55) )); then
val=$(do_facet mgs $LCTL get_param -n $nm_param)
[[ "$val" == "off" ]] ||
error "wrong default value $val for $nm_param"
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active 1
stack_trap cleanup_active EXIT
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0" EXIT
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0" EXIT
stack_trap "do_facet mgs $LCTL nodemap_set_cap \
--name default --type off" EXIT
# $DIR/$tdir/chown has CAP_CHOWN, so it should succeed with
# enable_cap_mask=off on nodemap
touch $DIR/$tdir/$tfile || error "touch $tfile as root (4)"
$RUNAS_CMD -u $ID0 $DIR/$tdir/chown $ID0 $DIR/$tdir/$tfile ||
error "chown $tfile as $ID0 (2)"
rm $DIR/$tdir/$tfile || error "rm $tfile (4)"
do_facet mgs $LCTL nodemap_set_cap --name default \
--type mask --caps cap_dac_read_search ||
error "nodemap_set_cap failed (1)"
wait_nm_sync default enable_cap_mask
# $DIR/$tdir/chown should fail with
# enable_cap_mask=mask:cap_dac_read_search on nodemap
touch $DIR/$tdir/$tfile || error "touch $tfile as root (5)"
$RUNAS_CMD -u $ID0 $DIR/$tdir/chown $ID0 $DIR/$tdir/$tfile &&
error "chown $tfile should fail (2)"
do_facet mgs $LCTL nodemap_set_cap --name default \
--type mask --caps +cap_chown ||
error "nodemap_set_cap failed (2)"
wait_nm_sync default enable_cap_mask
# $DIR/$tdir/chown should succeed with
# enable_cap_mask=mask:cap_chown,cap_dac_read_search
$RUNAS_CMD -u $ID0 $DIR/$tdir/chown $ID0 $DIR/$tdir/$tfile ||
error "chown $tfile as $ID0 (3)"
rm $DIR/$tdir/$tfile || error "rm $tfile (5)"
# Test ability to raise caps on child nodemap
do_facet mgs $LCTL nodemap_modify --name default \
--property child_raise_privileges --value none ||
error "setting child_raise_privileges=none failed"
wait_nm_sync default child_raise_privileges
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property child_raise_privileges --value none" EXIT
do_facet mds1 $LCTL nodemap_add -d -p default nm_51 ||
error "cannot create nodemap nm_51 (1)"
stack_trap "do_facet mds1 $LCTL nodemap_del nm_51" EXIT
do_facet mds1 $LCTL nodemap_set_cap --name nm_51 \
--type mask --caps +cap_fowner &&
error "nodemap_set_cap +cap_fowner should fail"
do_facet mds1 $LCTL nodemap_set_cap --name nm_51 \
--type mask --caps -cap_chown ||
error "nodemap_set_cap -cap_chown failed"
do_facet mds1 $LCTL nodemap_set_cap --name nm_51 \
--type mask --caps +cap_chown ||
error "nodemap_set_cap +cap_chown failed"
do_facet mds1 $LCTL nodemap_del nm_51 ||
error "cannot delete nodemap nm_51"
do_facet mgs $LCTL nodemap_modify --name default \
--property child_raise_privileges --value caps ||
error "setting child_raise_privileges=caps failed"
wait_nm_sync default child_raise_privileges
do_facet mds1 $LCTL nodemap_add -d -p default nm_51 ||
error "cannot create nodemap nm_51 (2)"
do_facet mds1 $LCTL nodemap_set_cap --name nm_51 \
--type mask --caps +cap_fowner ||
error "nodemap_set_cap +cap_fowner failed"
fi
}
run_test 51 "FS capabilities ==============="
test_52() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/$tfile
local mirror1=$TMP/$tfile.mirror1
local mirror2=$TMP/$tfile.mirror2
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $OSTCOUNT -lt 2 ]] && skip_env "needs >= 2 OSTs"
stack_trap "cleanup_for_enc_tests $tmpfile $mirror1 $mirror2" EXIT
setup_for_enc_tests
dd if=/dev/urandom of=$tmpfile bs=5000 count=1 conv=fsync
$LFS mirror create -N -i0 -N -i1 $testfile ||
error "could not create mirror"
dd if=$tmpfile of=$testfile bs=5000 count=1 conv=fsync ||
error "could not write to $testfile"
$LFS mirror resync $testfile ||
error "could not resync mirror"
$LFS mirror verify -v $testfile ||
error "verify mirror failed"
$LFS mirror read -N 1 -o $mirror1 $testfile ||
error "could not read from mirror 1"
cmp -bl $tmpfile $mirror1 ||
error "mirror 1 is corrupted"
$LFS mirror read -N 2 -o $mirror2 $testfile ||
error "could not read from mirror 2"
cmp -bl $tmpfile $mirror2 ||
error "mirror 2 is corrupted"
tr '\0' '2' < /dev/zero |
dd of=$tmpfile bs=1 count=9000 conv=fsync
$LFS mirror write -N 1 -i $tmpfile $testfile ||
error "could not write to mirror 1"
$LFS mirror verify -v $testfile &&
error "mirrors should be different"
rm -f $testfile $mirror1 $mirror2
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=9000 count=1 conv=fsync ||
error "write to $testfile failed"
$LFS getstripe $testfile
cancel_lru_locks
$LFS migrate -i1 $testfile ||
error "migrate $testfile failed"
$LFS getstripe $testfile
stripe=$($LFS getstripe -i $testfile)
[ $stripe -eq 1 ] || error "migrate file $testfile failed"
cancel_lru_locks
cmp -bl $tmpfile $testfile ||
error "migrated file is corrupted"
$LFS mirror extend -N -i0 $testfile ||
error "mirror extend $testfile failed"
$LFS getstripe $testfile
mirror_count=$($LFS getstripe -N $testfile)
[ $mirror_count -eq 2 ] ||
error "mirror extend file $testfile failed (1)"
stripe=$($LFS getstripe --mirror-id=1 -i $testfile)
[ $stripe -eq 1 ] || error "mirror extend file $testfile failed (2)"
stripe=$($LFS getstripe --mirror-id=2 -i $testfile)
[ $stripe -eq 0 ] || error "mirror extend file $testfile failed (3)"
cancel_lru_locks
$LFS mirror verify -v $testfile ||
error "mirror verify failed"
$LFS mirror read -N 1 -o $mirror1 $testfile ||
error "read from mirror 1 failed"
cmp -bl $tmpfile $mirror1 ||
error "corruption of mirror 1"
$LFS mirror read -N 2 -o $mirror2 $testfile ||
error "read from mirror 2 failed"
cmp -bl $tmpfile $mirror2 ||
error "corruption of mirror 2"
$LFS mirror split --mirror-id 1 -f ${testfile}.mirror $testfile &&
error "mirror split -f should fail"
$LFS mirror split --mirror-id 1 $testfile &&
error "mirror split without -d should fail"
$LFS mirror split --mirror-id 1 -d $testfile ||
error "mirror split failed"
$LFS getstripe $testfile
mirror_count=$($LFS getstripe -N $testfile)
[ $mirror_count -eq 1 ] ||
error "mirror split file $testfile failed (1)"
stripe=$($LFS getstripe --mirror-id=1 -i $testfile)
[ -z "$stripe" ] || error "mirror extend file $testfile failed (2)"
stripe=$($LFS getstripe --mirror-id=2 -i $testfile)
[ $stripe -eq 0 ] || error "mirror extend file $testfile failed (3)"
cancel_lru_locks
cmp -bl $tmpfile $testfile ||
error "extended/split file is corrupted"
}
run_test 52 "Mirrored encrypted file"
test_53() {
local testfile=$DIR/$tdir/$tfile
local testfile2=$DIR2/$tdir/$tfile
local tmpfile=$TMP/$tfile.tmp
local resfile=$TMP/$tfile.res
local pagesz
local filemd5
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
pagesz=$(getconf PAGESIZE)
[[ $pagesz == 65536 ]] || skip "Need 64K PAGE_SIZE client"
do_node $mds1_HOST \
"mount.lustre --help |& grep -q 'test_dummy_encryption:'" ||
skip "need dummy encryption support on MDS client mount"
# this test is probably useless now, but may turn out to be useful when
# Lustre supports servers with PAGE_SIZE != 4KB
pagesz=$(do_node $mds1_HOST getconf PAGESIZE)
[[ $pagesz == 4096 ]] || skip "Need 4K PAGE_SIZE MDS client"
stack_trap cleanup_for_enc_tests EXIT
stack_trap "zconf_umount $mds1_HOST $MOUNT2" EXIT
setup_for_enc_tests
$LFS setstripe -c1 -i0 $testfile
# write from 1st client
cat /dev/urandom | tr -dc 'a-zA-Z0-9' |
dd of=$tmpfile bs=$((pagesz+3)) count=2 conv=fsync
dd if=$tmpfile of=$testfile bs=$((pagesz+3)) count=2 conv=fsync ||
error "could not write to $testfile (1)"
# read from 2nd client
# mount and IOs must be done in the same shell session, otherwise
# encryption key in session keyring is missing
do_node $mds1_HOST "mkdir -p $MOUNT2"
do_node $mds1_HOST \
"$MOUNT_CMD -o ${MOUNT_OPTS},test_dummy_encryption \
$MGSNID:/$FSNAME $MOUNT2 && \
dd if=$testfile2 of=$resfile bs=$((pagesz+3)) count=2" ||
error "could not read from $testfile2 (1)"
# compare
filemd5=$(do_node $mds1_HOST md5sum $resfile | awk '{print $1}')
[ $filemd5 = $(md5sum $tmpfile | awk '{print $1}') ] ||
error "file is corrupted (1)"
do_node $mds1_HOST rm -f $resfile
cancel_lru_locks
# truncate from 2nd client
$TRUNCATE $tmpfile $((pagesz+3))
zconf_umount $mds1_HOST $MOUNT2 ||
error "umount $mds1_HOST $MOUNT2 failed (1)"
do_node $mds1_HOST "$MOUNT_CMD -o ${MOUNT_OPTS},test_dummy_encryption \
$MGSNID:/$FSNAME $MOUNT2 && \
$TRUNCATE $testfile2 $((pagesz+3))" ||
error "could not truncate $testfile2 (1)"
# compare
cmp -bl $tmpfile $testfile ||
error "file is corrupted (2)"
rm -f $tmpfile $testfile
cancel_lru_locks
zconf_umount $mds1_HOST $MOUNT2 ||
error "umount $mds1_HOST $MOUNT2 failed (2)"
# do conversly
do_node $mds1_HOST \
dd if=/dev/urandom of=$tmpfile bs=$((pagesz+3)) count=2 conv=fsync
# write from 2nd client
do_node $mds1_HOST \
"$MOUNT_CMD -o ${MOUNT_OPTS},test_dummy_encryption \
$MGSNID:/$FSNAME $MOUNT2 && \
dd if=$tmpfile of=$testfile2 bs=$((pagesz+3)) count=2 conv=fsync" ||
error "could not write to $testfile2 (2)"
# read from 1st client
dd if=$testfile of=$resfile bs=$((pagesz+3)) count=2 ||
error "could not read from $testfile (2)"
# compare
filemd5=$(do_node $mds1_HOST md5sum -b $tmpfile | awk '{print $1}')
[ $filemd5 = $(md5sum -b $resfile | awk '{print $1}') ] ||
error "file is corrupted (3)"
rm -f $resfile
cancel_lru_locks
# truncate from 1st client
do_node $mds1_HOST "$TRUNCATE $tmpfile $((pagesz+3))"
$TRUNCATE $testfile $((pagesz+3)) ||
error "could not truncate $testfile (2)"
# compare
zconf_umount $mds1_HOST $MOUNT2 ||
error "umount $mds1_HOST $MOUNT2 failed (3)"
do_node $mds1_HOST "$MOUNT_CMD -o ${MOUNT_OPTS},test_dummy_encryption \
$MGSNID:/$FSNAME $MOUNT2 && \
cmp -bl $tmpfile $testfile2" ||
error "file is corrupted (4)"
do_node $mds1_HOST rm -f $tmpfile
rm -f $tmpfile
}
run_test 53 "Mixed PAGE_SIZE clients"
test_54() {
local testdir=$DIR/$tdir/$ID0
local testdir2=$DIR2/$tdir/$ID0
local testfile=$testdir/$tfile
local testfile2=$testdir/${tfile}withveryverylongnametoexercisecode
local testfile3=$testdir/_${tfile}
local tmpfile=$TMP/${tfile}.tmp
local resfile=$TMP/${tfile}.res
local nameenc=""
local fid1
local fid2
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
which fscrypt || skip "This test needs fscrypt userspace tool"
yes | fscrypt setup --force --verbose ||
error "fscrypt global setup failed"
sed -i 's/\(.*\)policy_version\(.*\):\(.*\)\"[0-9]*\"\(.*\)/\1policy_version\2:\3"2"\4/' \
/etc/fscrypt.conf
yes | fscrypt setup --verbose $MOUNT ||
error "fscrypt setup $MOUNT failed"
mkdir -p $testdir
chown -R $ID0:$ID0 $testdir
echo -e 'mypass\nmypass' | su - $USER0 -c "fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector $testdir" ||
error "fscrypt encrypt failed"
echo -e 'mypass\nmypass' | su - $USER0 -c "fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector2 $testdir" &&
error "second fscrypt encrypt should have failed"
mkdir -p ${testdir}2 || error "mkdir ${testdir}2 failed"
touch ${testdir}2/f || error "mkdir ${testdir}2/f failed"
cancel_lru_locks
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector3 ${testdir}2 &&
error "fscrypt encrypt on non-empty dir should have failed"
$RUNAS dd if=/dev/urandom of=$testfile bs=127 count=1 conv=fsync ||
error "write to encrypted file $testfile failed"
cp $testfile $tmpfile
$RUNAS dd if=/dev/urandom of=$testfile2 bs=127 count=1 conv=fsync ||
error "write to encrypted file $testfile2 failed"
$RUNAS dd if=/dev/urandom of=$testfile3 bs=127 count=1 conv=fsync ||
error "write to encrypted file $testfile3 failed"
$RUNAS mkdir $testdir/subdir || error "mkdir subdir failed"
$RUNAS touch $testdir/subdir/subfile || error "mkdir subdir failed"
$RUNAS fscrypt lock --verbose $testdir ||
error "fscrypt lock $testdir failed (1)"
$RUNAS ls -R $testdir || error "ls -R $testdir failed"
local filecount=$($RUNAS find $testdir -type f | wc -l)
[ $filecount -eq 4 ] || error "found $filecount files"
# check enable_filename_encryption default value
# tunable only available for client built against embedded llcrypt
$LCTL get_param mdc.*.connect_flags | grep -q name_encryption &&
nameenc=$(lctl get_param -n llite.*.enable_filename_encryption |
head -n1)
# If client is built against in-kernel fscrypt, it is not possible
# to decide to encrypt file names or not: they are always encrypted.
if [ -n "$nameenc" ]; then
[ $nameenc -eq 0 ] ||
error "enable_filename_encryption should be 0 by default"
# $testfile, $testfile2 and $testfile3 should exist because
# names are not encrypted
[ -f $testfile ] ||
error "$testfile should exist because name not encrypted"
[ -f $testfile2 ] ||
error "$testfile2 should exist because name not encrypted"
[ -f $testfile3 ] ||
error "$testfile3 should exist because name not encrypted"
stat $testfile3
[ $? -eq 0 ] || error "cannot stat $testfile3 without key"
fi
scrambledfiles=( $(find $testdir/ -maxdepth 1 -type f) )
$RUNAS hexdump -C ${scrambledfiles[0]} &&
error "reading ${scrambledfiles[0]} should fail without key"
$RUNAS touch ${testfile}.nokey &&
error "touch ${testfile}.nokey should have failed without key"
echo mypass | $RUNAS fscrypt unlock --verbose $testdir ||
error "fscrypt unlock $testdir failed (1)"
$RUNAS cat $testfile > $resfile ||
error "reading $testfile failed"
cmp -bl $tmpfile $resfile || error "file read differs from file written"
stat $testfile3
[ $? -eq 0 ] || error "cannot stat $testfile3 with key"
$RUNAS fscrypt lock --verbose $testdir ||
error "fscrypt lock $testdir failed (2)"
$RUNAS hexdump -C ${scrambledfiles[1]} &&
error "reading ${scrambledfiles[1]} should fail without key"
# server local client incompatible with SSK keys installed
if [ "$SHARED_KEY" != true ]; then
mount_mds_client
stack_trap umount_mds_client EXIT
do_facet $SINGLEMDS touch $DIR2/$tdir/newfile
mdsscrambledfile=$(do_facet $SINGLEMDS find $testdir2/ \
-maxdepth 1 -type f | head -n1)
[ -n "$mdsscrambledfile" ] || error "could not find file"
do_facet $SINGLEMDS cat "$mdsscrambledfile" &&
error "reading $mdsscrambledfile should fail on MDS"
do_facet $SINGLEMDS "echo aaa >> \"$mdsscrambledfile\"" &&
error "writing $mdsscrambledfile should fail on MDS"
do_facet $SINGLEMDS $MULTIOP $testdir2/fileA m &&
error "creating $testdir2/fileA should fail on MDS"
do_facet $SINGLEMDS mkdir $testdir2/dirA &&
error "mkdir $testdir2/dirA should fail on MDS"
do_facet $SINGLEMDS ln -s $DIR2/$tdir/newfile $testdir2/sl1 &&
error "ln -s $testdir2/sl1 should fail on MDS"
do_facet $SINGLEMDS ln $DIR2/$tdir/newfile $testdir2/hl1 &&
error "ln $testdir2/hl1 should fail on MDS"
do_facet $SINGLEMDS mv "$mdsscrambledfile" $testdir2/fB &&
error "mv $mdsscrambledfile should fail on MDS"
do_facet $SINGLEMDS mrename "$mdsscrambledfile" $testdir2/fB &&
error "mrename $mdsscrambledfile should fail on MDS"
do_facet $SINGLEMDS rm -f $DIR2/$tdir/newfile
fi
echo mypass | $RUNAS fscrypt unlock --verbose $testdir ||
error "fscrypt unlock $testdir failed (2)"
rm -rf $testdir/*
$RUNAS fscrypt lock --verbose $testdir ||
error "fscrypt lock $testdir failed (3)"
rm -rf $tmpfile $resfile $testdir ${testdir}2 $MOUNT/.fscrypt
# remount client with subdirectory mount
umount_client $MOUNT || error "umount $MOUNT failed (1)"
export FILESET=/$tdir
mount_client $MOUNT ${MOUNT_OPTS} || error "remount failed (1)"
export FILESET=""
wait_ssk
# setup encryption from inside this subdir mount
# the .fscrypt directory is going to be created at the real fs root
yes | fscrypt setup --verbose $MOUNT ||
error "fscrypt setup $MOUNT failed (2)"
testdir=$MOUNT/vault
mkdir $testdir
chown -R $ID0:$ID0 $testdir
fid1=$(path2fid $MOUNT/.fscrypt)
echo "With FILESET $tdir, .fscrypt FID is $fid1"
# enable name encryption, only valid if built against embedded llcrypt
if [ -n "$nameenc" ]; then
do_facet mgs $LCTL set_param -P \
llite.*.enable_filename_encryption=1
[ $? -eq 0 ] ||
error "set_param -P \
llite.*.enable_filename_encryption failed"
wait_update_facet --verbose client \
"$LCTL get_param -n llite.*.enable_filename_encryption \
| head -n1" 1 30 ||
error "enable_filename_encryption not set on client"
fi
# encrypt 'vault' dir inside the subdir mount
echo -e 'mypass\nmypass' | su - $USER0 -c "fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector $testdir" ||
error "fscrypt encrypt failed"
echo abc > $tmpfile
chmod 666 $tmpfile
$RUNAS cp $tmpfile $testdir/encfile
$RUNAS fscrypt lock --verbose $testdir ||
error "fscrypt lock $testdir failed (4)"
# encfile should actually have its name encrypted
if [ -n "$nameenc" ]; then
[ -f $testdir/encfile ] &&
error "encfile name should be encrypted"
fi
filecount=$(find $testdir -type f | wc -l)
[ $filecount -eq 1 ] || error "found $filecount files instead of 1"
# remount client with encrypted dir as subdirectory mount
umount_client $MOUNT || error "umount $MOUNT failed (2)"
export FILESET=/$tdir/vault
mount_client $MOUNT ${MOUNT_OPTS} || error "remount failed (2)"
export FILESET=""
wait_ssk
ls -laR $MOUNT
fid2=$(path2fid $MOUNT/.fscrypt)
echo "With FILESET $tdir/vault, .fscrypt FID is $fid2"
[ "$fid1" == "$fid2" ] || error "fid1 $fid1 != fid2 $fid2 (1)"
# all content seen by this mount is encrypted, but .fscrypt is virtually
# presented, letting us call fscrypt lock/unlock
echo mypass | $RUNAS fscrypt unlock --verbose $MOUNT ||
error "fscrypt unlock $MOUNT failed (3)"
ls -laR $MOUNT
[ $(cat $MOUNT/encfile) == "abc" ] || error "cat encfile failed"
# remount client without subdir mount
umount_client $MOUNT || error "umount $MOUNT failed (3)"
mount_client $MOUNT ${MOUNT_OPTS} || error "remount failed (3)"
wait_ssk
ls -laR $MOUNT
fid2=$(path2fid $MOUNT/.fscrypt)
echo "Without FILESET, .fscrypt FID is $fid2"
[ "$fid1" == "$fid2" ] || error "fid1 $fid1 != fid2 $fid2 (2)"
# because .fscrypt was actually created at the real root of the fs,
# we can call fscrypt lock/unlock on the encrypted dir
echo mypass | $RUNAS fscrypt unlock --verbose $DIR/$tdir/vault ||
error "fscrypt unlock $$DIR/$tdir/vault failed (4)"
ls -laR $MOUNT
echo c >> $DIR/$tdir/vault/encfile || error "write to encfile failed"
rm -rf $DIR/$tdir/vault/*
$RUNAS fscrypt lock --verbose $DIR/$tdir/vault ||
error "fscrypt lock $DIR/$tdir/vault failed (5)"
# disable name encryption, only valid if built against embedded llcrypt
if [ -n "$nameenc" ]; then
do_facet mgs $LCTL set_param -P \
llite.*.enable_filename_encryption=0
[ $? -eq 0 ] ||
error "set_param -P \
llite.*.enable_filename_encryption failed"
wait_update_facet --verbose client \
"$LCTL get_param -n llite.*.enable_filename_encryption \
| head -n1" 0 30 ||
error "enable_filename_encryption not set back to default"
fi
rm -rf $tmpfile $MOUNT/.fscrypt
}
run_test 54 "Encryption policies with fscrypt"
setup_local_client_nodemap() {
local nm_name=${1:-"c0"}
local nm_admin_val=${2:-0}
local nm_trusted_val=${3:-0}
local nm_cli=${4:-$HOSTNAME}
local needremount=false
local needremount2=false
local rc
if $SHARED_KEY; then
export SK_UNIQUE_NM=true
export FILESET="/"
if $(do_node $nm_cli cat /proc/mounts | grep lustre |
grep -wq $MOUNT); then
zconf_umount $nm_cli $MOUNT ||
error "umount $MOUNT failed"
needremount=true
fi
if $(do_node $nm_cli cat /proc/mounts | grep lustre |
grep -wq $MOUNT2); then
zconf_umount $nm_cli $MOUNT2 ||
error "umount $MOUNT2 failed"
needremount2=true
fi
# Load per-NM key on servers
do_nodes $(comma_list $(all_server_nodes)) \
"$LGSS_SK -t server -l $SK_PATH/nodemap/${nm_name}.key"
fi
do_facet mgs $LCTL nodemap_del $nm_name || true
wait_nm_sync $nm_name id ''
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
wait_nm_sync default trusted_nodemap
client_ip=$(host_nids_address $nm_cli $NETTYPE)
client_nid=$(h2nettype $client_ip)
do_facet mgs $LCTL nodemap_add $nm_name
do_facet mgs $LCTL nodemap_add_range \
--name $nm_name --range $client_nid ||
error "Add range $client_nid to $nm_name failed rc = $?"
do_facet mgs $LCTL nodemap_modify --name $nm_name \
--property admin --value $nm_admin_val
do_facet mgs $LCTL nodemap_modify --name $nm_name \
--property trusted --value $nm_trusted_val
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
$needremount && {
zconf_mount $nm_cli $MOUNT ${MOUNT_OPTS} ||
error "remount $MOUNT failed"
}
$needremount2 && {
zconf_mount $nm_cli $MOUNT2 ${MOUNT_OPTS} ||
error "remount $MOUNT2 failed"
}
wait_ssk
}
set_nodemap_rbac() {
local nm_name=$1
local rbac=$2
do_facet mgs $LCTL nodemap_modify --name $nm_name --property rbac \
--value $rbac || error "setting $nm_name rbac $rbac failed"
wait_nm_sync $nm_name rbac
}
cleanup_local_client_nodemap() {
local nm_name=${1:-"c0"}
local needremount2=false
if $SHARED_KEY; then
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
needremount2=true
fi
fi
do_facet mgs $LCTL nodemap_del $nm_name || true
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0
do_facet mgs $LCTL nodemap_activate 0
wait_nm_sync active 0
if $SHARED_KEY; then
unset FILESET
export SK_UNIQUE_NM=false
fi
if ! is_mounted $MOUNT; then
mount_client $MOUNT ${MOUNT_OPTS} || error "re-mount failed"
fi
$needremount2 && {
mount_client $MOUNT2 ${MOUNT_OPTS} ||
error "remount $MOUNT2 failed"
}
wait_ssk
}
cleanup_local_client_nodemap_with_mounts() {
# unmount client
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# reset and deactivate nodemaps, remount client
cleanup_local_client_nodemap
# remount client on $MOUNT_2
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} || error "remount failed"
fi
wait_ssk
}
test_55() {
(( $MDS1_VERSION > $(version_code v2_12_6-3-g02b04c64a8) )) ||
skip "Need MDS version at least 2.12.6.3"
local client_ip
local client_nid
mkdir -p $DIR/$tdir/$USER0/testdir_groups
chown root:$USER0 $DIR/$tdir/$USER0
chmod 770 $DIR/$tdir/$USER0
chmod g+s $DIR/$tdir/$USER0
chown $USER0:$USER0 $DIR/$tdir/$USER0/testdir_groups
chmod 770 $DIR/$tdir/$USER0/testdir_groups
chmod g+s $DIR/$tdir/$USER0/testdir_groups
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
do_nodes $(all_mdts_nodes) "$LCTL set_param mdt.*.identity_upcall=NONE"
stack_trap cleanup_local_client_nodemap_with_mounts EXIT
setup_local_client_nodemap "c0" 0 1
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed"
unset FILESET
wait_ssk
euid_access $USER0 $DIR/$tdir/$USER0/testdir_groups/file
}
run_test 55 "access with seteuid"
test_56() {
local filefrag_op=$(filefrag -l 2>&1 | grep "invalid option")
[[ -z "$filefrag_op" ]] || skip_env "filefrag missing logical ordering"
local testfile=$DIR/$tdir/$tfile
[[ $(facet_fstype ost1) == zfs ]] && skip "skip ZFS backend"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $OSTCOUNT -lt 2 ]] && skip_env "needs >= 2 OSTs"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
$LFS setstripe -c1 $testfile
dd if=/dev/urandom of=$testfile bs=1M count=3 conv=fsync
filefrag -v $testfile || error "filefrag $testfile failed"
(( $(filefrag -v $testfile | grep -c encrypted) >= 1 )) ||
error "filefrag $testfile does not show encrypted flag"
(( $(filefrag -v $testfile | grep -c encoded) >= 1 )) ||
error "filefrag $testfile does not show encoded flag"
}
run_test 56 "FIEMAP on encrypted file"
test_57() {
local testdir=$DIR/$tdir/mytestdir
local testfile=$DIR/$tdir/$tfile
[[ $(facet_fstype ost1) == zfs ]] && skip "skip ZFS backend"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
mkdir $DIR/$tdir
mkdir $testdir
setfattr -n security.c -v myval $testdir &&
error "setting xattr on $testdir should have failed (1.1)"
setfattr -n encryption.c -v myval $testdir &&
error "setting xattr on $testdir should have failed (1.2)"
touch $testfile
setfattr -n security.c -v myval $testfile &&
error "setting xattr on $testfile should have failed (1.1)"
setfattr -n encryption.c -v myval $testfile &&
error "setting xattr on $testfile should have failed (1.2)"
rm -rf $DIR/$tdir
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
mkdir $testdir
if [ $(getfattr -n security.c $testdir 2>&1 |
grep -ci "Operation not permitted") -eq 0 ]; then
error "getting xattr on $testdir should have failed (1.1)"
fi
if [ $(getfattr -n encryption.c $testdir 2>&1 |
grep -ci "Operation not supported") -eq 0 ]; then
error "getting xattr on $testdir should have failed (1.2)"
fi
getfattr -d -m - $testdir 2>&1 | grep security\.c &&
error "listing xattrs on $testdir should not expose security.c"
getfattr -d -m - $testdir 2>&1 | grep encryption\.c &&
error "listing xattrs on $testdir should not expose encryption.c"
if [ $(setfattr -n security.c -v myval $testdir 2>&1 |
grep -ci "Operation not permitted") -eq 0 ]; then
error "setting xattr on $testdir should have failed (2.1)"
fi
if [ $(setfattr -n encryption.c -v myval $testdir 2>&1 |
grep -ci "Operation not supported") -eq 0 ]; then
error "setting xattr on $testdir should have failed (2.2)"
fi
touch $testfile
if [ $(getfattr -n security.c $testfile 2>&1 |
grep -ci "Operation not permitted") -eq 0 ]; then
error "getting xattr on $testfile should have failed (1.1)"
fi
if [ $(getfattr -n encryption.c $testfile 2>&1 |
grep -ci "Operation not supported") -eq 0 ]; then
error "getting xattr on $testfile should have failed (1.2)"
fi
getfattr -d -m - $testfile 2>&1 | grep security\.c &&
error "listing xattrs on $testfile should not expose security.c"
getfattr -d -m - $testfile 2>&1 | grep encryption\.c &&
error "listing xattrs on $testfile should not expose encryption.c"
if [ $(setfattr -n security.c -v myval $testfile 2>&1 |
grep -ci "Operation not permitted") -eq 0 ]; then
error "setting xattr on $testfile should have failed (2.1)"
fi
if [ $(setfattr -n encryption.c -v myval $testfile 2>&1 |
grep -ci "Operation not supported") -eq 0 ]; then
error "setting xattr on $testfile should have failed (2.2)"
fi
return 0
}
run_test 57 "security.c/encryption.c xattr protection"
test_58() {
local testdir=$DIR/$tdir/mytestdir
local testfile=$DIR/$tdir/$tfile
[[ $(facet_fstype ost1) == zfs ]] && skip "skip ZFS backend"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
touch $DIR/$tdir/$tfile
mkdir $DIR/$tdir/subdir
cancel_lru_locks
sync ; sync
echo 3 > /proc/sys/vm/drop_caches
ll_decode_linkea $DIR/$tdir/$tfile || error "cannot read $tfile linkea"
ll_decode_linkea $DIR/$tdir/subdir || error "cannot read subdir linkea"
for ((i = 0; i < 1000; i = $((i+1)))); do
mkdir -p $DIR/$tdir/d${i}
touch $DIR/$tdir/f${i}
createmany -m $DIR/$tdir/d${i}/f 5 > /dev/null
done
cancel_lru_locks
sync ; sync
echo 3 > /proc/sys/vm/drop_caches
sleep 10
ls -ailR $DIR/$tdir > /dev/null || error "fail to ls"
}
run_test 58 "access to enc file's xattrs"
verify_mirror() {
local mirror1=$TMP/$tfile.mirror1
local mirror2=$TMP/$tfile.mirror2
local testfile=$1
local reffile=$2
$LFS mirror verify -vvv $testfile ||
error "verifying mirror failed (1)"
if [ $($LFS mirror verify -v $testfile 2>&1 |
grep -ci "only valid") -ne 0 ]; then
error "verifying mirror failed (2)"
fi
$LFS mirror read -N 1 -o $mirror1 $testfile ||
error "read from mirror 1 failed"
cmp -bl $reffile $mirror1 ||
error "corruption of mirror 1"
$LFS mirror read -N 2 -o $mirror2 $testfile ||
error "read from mirror 2 failed"
cmp -bl $reffile $mirror2 ||
error "corruption of mirror 2"
}
test_59a() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/$tfile
local mirror1=$TMP/$tfile.mirror1
local mirror2=$TMP/$tfile.mirror2
local scrambledfile
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $OSTCOUNT -lt 2 ]] && skip_env "needs >= 2 OSTs"
stack_trap "cleanup_for_enc_tests $tmpfile $mirror1 $mirror2" EXIT
setup_for_enc_tests
dd if=/dev/urandom of=$tmpfile bs=5000 count=1 conv=fsync
$LFS mirror create -N -i0 -N -i1 $testfile ||
error "could not create mirror"
dd if=$tmpfile of=$testfile bs=5000 count=1 conv=fsync ||
error "could not write to $testfile"
$LFS getstripe $testfile
# remount without dummy encryption key
remount_client_normally
scrambledfile=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type f)
$LFS mirror resync $scrambledfile ||
error "could not resync mirror"
$LFS mirror verify -vvv $scrambledfile ||
error "mirror verify failed (1)"
if [ $($LFS mirror verify -v $scrambledfile 2>&1 |
grep -ci "only valid") -ne 0 ]; then
error "mirror verify failed (2)"
fi
$LFS mirror read -N 1 -o $mirror1 $scrambledfile &&
error "read from mirror should fail"
# now, with the key
remount_client_dummykey
verify_mirror $testfile $tmpfile
}
run_test 59a "mirror resync of encrypted files without key"
test_59b() {
local testfile=$DIR/$tdir/$tfile
local tmpfile=$TMP/$tfile
local mirror1=$TMP/$tfile.mirror1
local mirror2=$TMP/$tfile.mirror2
local scrambledfile
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $OSTCOUNT -lt 2 ]] && skip_env "needs >= 2 OSTs"
stack_trap "cleanup_for_enc_tests $tmpfile $mirror1 $mirror2" EXIT
setup_for_enc_tests
tr '\0' '2' < /dev/zero |
dd of=$tmpfile bs=1 count=9000 conv=fsync
$LFS setstripe -c1 -i0 $testfile
dd if=$tmpfile of=$testfile bs=9000 count=1 conv=fsync ||
error "write to $testfile failed"
$LFS getstripe $testfile
# remount without dummy encryption key
remount_client_normally
scrambledfile=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type f)
$LFS migrate -i1 $scrambledfile ||
error "migrate $scrambledfile failed"
$LFS getstripe $scrambledfile
stripe=$($LFS getstripe -i $scrambledfile)
[ $stripe -eq 1 ] || error "migrate file $scrambledfile failed"
cancel_lru_locks
# now, with the key
remount_client_dummykey
cmp -bl $tmpfile $testfile ||
error "migrated file is corrupted"
# remount without dummy encryption key
remount_client_normally
$LFS mirror extend -N -i0 $scrambledfile ||
error "mirror extend $scrambledfile failed (1)"
$LFS getstripe $scrambledfile
mirror_count=$($LFS getstripe -N $scrambledfile)
[ $mirror_count -eq 2 ] ||
error "mirror extend file $scrambledfile failed (2)"
stripe=$($LFS getstripe --mirror-id=1 -i $scrambledfile)
[ $stripe -eq 1 ] ||
error "mirror extend file $scrambledfile failed (3)"
stripe=$($LFS getstripe --mirror-id=2 -i $scrambledfile)
[ $stripe -eq 0 ] ||
error "mirror extend file $scrambledfile failed (4)"
$LFS mirror verify -vvv $scrambledfile ||
error "mirror verify failed (1)"
if [ $($LFS mirror verify -v $scrambledfile 2>&1 |
grep -ci "only valid") -ne 0 ]; then
error "mirror verify failed (2)"
fi
# now, with the key
remount_client_dummykey
verify_mirror $testfile $tmpfile
# remount without dummy encryption key
remount_client_normally
$LFS mirror split --mirror-id 1 -d $scrambledfile ||
error "mirror split file $scrambledfile failed (1)"
$LFS getstripe $scrambledfile
mirror_count=$($LFS getstripe -N $scrambledfile)
[ $mirror_count -eq 1 ] ||
error "mirror split file $scrambledfile failed (2)"
stripe=$($LFS getstripe --mirror-id=1 -i $scrambledfile)
[ -z "$stripe" ] || error "mirror split file $scrambledfile failed (3)"
stripe=$($LFS getstripe --mirror-id=2 -i $scrambledfile)
[ $stripe -eq 0 ] || error "mirror split file $scrambledfile failed (4)"
# now, with the key
remount_client_dummykey
cancel_lru_locks
cmp -bl $tmpfile $testfile ||
error "extended/split file is corrupted"
}
run_test 59b "migrate/extend/split of encrypted files without key"
test_59c() {
local dirname=$DIR/$tdir/subdir
local scrambleddir
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
[[ $MDSCOUNT -ge 2 ]] || skip_env "needs >= 2 MDTs"
(( "$MDS1_VERSION" > $(version_code 2.14.54.54) )) ||
skip "MDT migration not supported with older server"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
$LFS setdirstripe -i 0 $dirname
echo b > $dirname/subf
# remount without dummy encryption key
remount_client_normally
scrambleddir=$(find $DIR/$tdir/ -maxdepth 1 -mindepth 1 -type d)
# migrate a non-empty encrypted dir
$LFS migrate -m 1 $scrambleddir ||
error "migrate $scrambleddir between MDTs failed (1)"
stripe=$($LFS getdirstripe -i $scrambleddir)
[ $stripe -eq 1 ] ||
error "migrate $scrambleddir between MDTs failed (2)"
# now, with the key
insert_enc_key
[ -f $dirname/subf ] ||
error "migrate $scrambleddir between MDTs failed (3)"
[ $(cat $dirname/subf) == "b" ] ||
error "migrate $scrambleddir between MDTs failed (4)"
}
run_test 59c "MDT migrate of encrypted files without key"
test_60() {
local testdir=$DIR/$tdir/mytestdir
local testfile=$DIR/$tdir/$tfile
(( $MDS1_VERSION > $(version_code 2.14.53) )) ||
skip "Need MDS version at least 2.14.53"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
echo a > $DIR/$tdir/file1
mkdir $DIR/$tdir/subdir
echo b > $DIR/$tdir/subdir/subfile1
remove_enc_key
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# remount client with subdirectory mount
export FILESET=/$tdir
mount_client $MOUNT ${MOUNT_OPTS} || error "remount failed"
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} || error "remount failed"
fi
wait_ssk
ls -Rl $DIR || error "ls -Rl $DIR failed (1)"
# now, with the key
remount_client_dummykey
export FILESET=""
ls -Rl $DIR || error "ls -Rl $DIR failed (2)"
cat $DIR/file1 || error "cat $DIR/$tdir/file1 failed"
cat $DIR/subdir/subfile1 ||
error "cat $DIR/$tdir/subdir/subfile1 failed"
}
run_test 60 "Subdirmount of encrypted dir"
test_61() {
local testfile=$DIR/$tdir/$tfile
local readonly
readonly=$(do_facet mgs \
lctl get_param -n nodemap.default.readonly_mount)
[ -n "$readonly" ] ||
skip "Server does not have readonly_mount nodemap flag"
stack_trap cleanup_local_client_nodemap EXIT
for idx in $(seq 1 $MDSCOUNT); do
wait_recovery_complete mds$idx
done
umount_client $MOUNT || error "umount $MOUNT failed (1)"
# Activate nodemap, and mount rw.
# Should succeed as rw mount is not forbidden by default.
setup_local_client_nodemap "c0" 1 1
readonly=$(do_facet mgs \
lctl get_param -n nodemap.default.readonly_mount)
[ $readonly -eq 0 ] ||
error "wrong default value for readonly_mount on default nodemap"
readonly=$(do_facet mgs \
lctl get_param -n nodemap.c0.readonly_mount)
[ $readonly -eq 0 ] ||
error "wrong default value for readonly_mount on nodemap c0"
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS},rw ||
error "mount '-o rw' failed with default"
wait_ssk
findmnt $MOUNT --output=options -n -f | grep -q "rw," ||
error "should be rw mount"
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
echo a > $testfile || error "write $testfile failed"
umount_client $MOUNT || error "umount $MOUNT failed (2)"
# Now enforce read-only, and retry.
do_facet mgs $LCTL nodemap_modify --name c0 \
--property readonly_mount --value 1
wait_nm_sync c0 readonly_mount
# mount without option should turn into ro
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS} ||
error "mount failed (1)"
findmnt $MOUNT --output=options -n -f | grep -q "ro," ||
error "mount should have been turned into ro"
cat $testfile || error "read $testfile failed (1)"
echo b > $testfile && error "write $testfile should fail (1)"
umount_client $MOUNT || error "umount $MOUNT failed (3)"
# mount rw should turn into ro
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS},rw ||
error "mount '-o rw' failed"
findmnt $MOUNT --output=options -n -f | grep -q "ro," ||
error "mount rw should have been turned into ro"
cat $testfile || error "read $testfile failed (2)"
echo b > $testfile && error "write $testfile should fail (2)"
umount_client $MOUNT || error "umount $MOUNT failed (4)"
# mount ro should work as expected
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS},ro ||
error "mount '-o ro' failed"
wait_ssk
cat $testfile || error "read $testfile failed (3)"
echo b > $testfile && error "write $testfile should fail (3)"
umount_client $MOUNT || error "umount $MOUNT failed (5)"
# remount rw should not work
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS} ||
error "mount failed (2)"
mount_client $MOUNT remount,rw || error "remount failed"
findmnt $MOUNT --output=options -n -f | grep -q "ro," ||
error "remount rw should have been turned into ro"
cat $testfile || error "read $testfile failed (4)"
echo b > $testfile && error "write $testfile should fail (4)"
umount_client $MOUNT || error "umount $MOUNT failed (6)"
}
run_test 61 "Nodemap enforces read-only mount"
test_62() {
local testdir=$DIR/$tdir/mytestdir
local testfile=$DIR/$tdir/$tfile
[[ $(facet_fstype ost1) == zfs ]] && skip "skip ZFS backend"
(( $MDS1_VERSION > $(version_code 2.15.51) )) ||
skip "Need MDS version at least 2.15.51"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
lfs setstripe -c -1 $DIR/$tdir
touch $DIR/$tdir/${tfile}_1 || error "touch ${tfile}_1 failed"
dd if=/dev/zero of=$DIR/$tdir/${tfile}_2 bs=1 count=1 conv=fsync ||
error "dd ${tfile}_2 failed"
# unmount the Lustre filesystem
stopall || error "stopping for e2fsck run"
# run e2fsck on the MDT and OST devices
local mds_host=$(facet_active_host $SINGLEMDS)
local ost_host=$(facet_active_host ost1)
local mds_dev=$(mdsdevname ${SINGLEMDS//mds/})
local ost_dev=$(ostdevname 1)
run_e2fsck $mds_host $mds_dev "-n"
run_e2fsck $ost_host $ost_dev "-n"
# mount the Lustre filesystem
setupall || error "remounting the filesystem failed"
}
run_test 62 "e2fsck with encrypted files"
create_files() {
local path
for path in "${paths[@]}"; do
touch $path
done
}
build_fids() {
local path
for path in "${paths[@]}"; do
fids+=("$(lfs path2fid $path)")
done
}
check_fids() {
for fid in "${fids[@]}"; do
echo $fid
respath=$(lfs fid2path $MOUNT $fid)
echo -e "\t" $respath
ls -li $respath >/dev/null
[ $? -eq 0 ] || error "fid2path $fid failed"
done
}
test_63() {
declare -a fids
declare -a paths
local vaultdir1=$DIR/$tdir/vault1==dir
local vaultdir2=$DIR/$tdir/vault2==dir
local longfname1="longfilenamewitha=inthemiddletotestbehaviorregardingthedigestedform"
local longdname="longdirectorynamewitha=inthemiddletotestbehaviorregardingthedigestedform"
local longfname2="$longdname/${longfname1}2"
(( $MDS1_VERSION > $(version_code 2.15.53) )) ||
skip "Need MDS version at least 2.15.53"
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
which fscrypt || skip "This test needs fscrypt userspace tool"
yes | fscrypt setup --force --verbose ||
echo "fscrypt global setup already done"
sed -i 's/\(.*\)policy_version\(.*\):\(.*\)\"[0-9]*\"\(.*\)/\1policy_version\2:\3"2"\4/' \
/etc/fscrypt.conf
yes | fscrypt setup --verbose $MOUNT ||
echo "fscrypt setup $MOUNT already done"
# enable_filename_encryption tunable only available for client
# built against embedded llcrypt. If client is built against in-kernel
# fscrypt, file names are always encrypted.
$LCTL get_param mdc.*.connect_flags | grep -q name_encryption &&
nameenc=$(lctl get_param -n llite.*.enable_filename_encryption |
head -n1)
if [ -n "$nameenc" ]; then
do_facet mgs $LCTL set_param -P \
llite.*.enable_filename_encryption=1
[ $? -eq 0 ] ||
error "set_param -P \
llite.*.enable_filename_encryption=1 failed"
wait_update_facet --verbose client \
"$LCTL get_param -n llite.*.enable_filename_encryption \
| head -n1" 1 30 ||
error "enable_filename_encryption not set on client"
fi
mkdir -p $vaultdir1
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_63_1 $vaultdir1 ||
error "fscrypt encrypt $vaultdir1 failed"
mkdir $vaultdir1/dirA
mkdir $vaultdir1/$longdname
paths=("$vaultdir1/fileA")
paths+=("$vaultdir1/dirA/fileB")
paths+=("$vaultdir1/$longfname1")
paths+=("$vaultdir1/$longfname2")
create_files
paths+=("$vaultdir1/dirA")
paths+=("$vaultdir1/$longdname")
build_fids
check_fids
fscrypt lock --verbose $vaultdir1 ||
error "fscrypt lock $vaultdir1 failed (1)"
check_fids
if [ -z "$nameenc" ]; then
echo "Rest of the test requires disabling name encryption"
exit 0
fi
# disable name encryption
do_facet mgs $LCTL set_param -P llite.*.enable_filename_encryption=0
[ $? -eq 0 ] ||
error "set_param -P llite.*.enable_filename_encryption=0 failed"
wait_update_facet --verbose client \
"$LCTL get_param -n llite.*.enable_filename_encryption \
| head -n1" 0 30 ||
error "enable_filename_encryption not set back to default"
mkdir -p $vaultdir2
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_63_2 $vaultdir2 ||
error "fscrypt encrypt $vaultdir2 failed"
mkdir $vaultdir2/dirA
mkdir $vaultdir2/$longdname
paths=()
fids=()
paths=("$vaultdir2/fileA")
paths+=("$vaultdir2/dirA/fileB")
paths+=("$vaultdir2/$longfname1")
paths+=("$vaultdir2/$longfname2")
create_files
paths+=("$vaultdir2/dirA")
paths+=("$vaultdir2/$longdname")
build_fids
check_fids
fscrypt lock --verbose $vaultdir2 ||
error "fscrypt lock $vaultdir2 failed (2)"
check_fids
rm -rf $MOUNT/.fscrypt
}
run_test 63 "fid2path with encrypted files"
setup_defaultnm_for_64() {
cleanup_local_client_nodemap
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
}
cleanup_defaultnm_for_64() {
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac --value all
wait_nm_sync default rbac
}
test_64a() {
local testfile=$DIR/$tdir/$tfile
local srv_uc=""
local local_admin=""
local pool_quota=""
local lqa_quota=""
local rbac
(( MDS1_VERSION >= $(version_code v2_15_54-111-g971e025f5f) )) ||
skip "Need MDS >= 2.15.54.111 for role-based controls"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
(( MDS1_VERSION >= $(version_code v2_16_52-135-gf7495bc57f) )) &&
local_admin="local_admin"
(( MDS1_VERSION >= $(version_code v2_16_57-139-g8b2d38ee74) )) &&
pool_quota="pool_quota_ops"
(( MDS1_VERSION >= $(version_code v2_17_52-1-gedcf58d579) )) &&
lqa_quota="lqa_quota_ops"
(( MDS1_VERSION >= $(version_code 2.17.52) )) &&
projid_set="projid_set"
(( MDS1_VERSION >= $(version_code 2.17.52) )) &&
foreign_ops="foreign_ops"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
# check default value for rbac is all
rbac=$(do_facet mds $LCTL get_param -n nodemap.c0.rbac)
for role in file_perms \
dne_ops \
quota_ops \
byfid_ops \
chlg_ops \
fscrypt_admin \
$srv_uc \
$local_admin \
$pool_quota \
$lqa_quota \
$projid_set \
$foreign_ops \
;
do
[[ "$rbac" =~ "$role" ]] ||
error "role '$role' not in default '$rbac'"
done
# projid_set is required for 'lfs project'
rbac="projid_set,file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value $rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
touch $testfile
stack_trap "set +vx"
set -vx
chmod 777 $testfile || error "chmod failed"
chown $TSTUSR:$TSTUSR $testfile || error "chown failed"
chgrp $TSTUSR $testfile || error "chgrp failed"
$LFS project -p 1000 $testfile || error "setting project failed"
set +vx
rm -f $testfile
rbac="projid_set"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
touch $testfile
set -vx
chmod 777 $testfile && error "chmod should fail"
chown $TSTUSR:$TSTUSR $testfile && error "chown should fail"
chgrp $TSTUSR $testfile && error "chgrp should fail"
$LFS project -p 1000 $testfile && error "setting project should fail"
set +vx
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
# Check default value for rbac is all on default nodemap
rbac=$(do_facet mds $LCTL get_param -n nodemap.default.rbac)
for role in file_perms \
dne_ops \
quota_ops \
byfid_ops \
chlg_ops \
fscrypt_admin \
$srv_uc \
$pool_quota \
$lqa_quota \
$projid_set \
;
do
[[ "$rbac" =~ "$role" ]] ||
error "role '$role' not in '$rbac' on default nodemap"
done
stack_trap cleanup_defaultnm_for_64
rbac="projid_set,file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
touch $testfile
set -vx
chmod 777 $testfile || error "chmod failed on default nodemap"
chown $TSTUSR:$TSTUSR $testfile ||
error "chown failed on default nodemap"
chgrp $TSTUSR $testfile || error "chgrp failed on default nodemap"
$LFS project -p 1000 $testfile ||
error "setting project failed on default nodemap"
set +vx
rm -f $testfile
rbac="projid_set"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
touch $testfile
set -vx
chmod 777 $testfile && error "chmod should fail on default nodemap"
chown $TSTUSR:$TSTUSR $testfile &&
error "chown should fail on default nodemap"
chgrp $TSTUSR $testfile &&
error "chgrp should fail on default nodemap"
$LFS project -p 1000 $testfile &&
error "setting project should fail on default nodemap"
set +vx
}
run_test 64a "Nodemap enforces file_perms RBAC roles"
test_64b() {
local testdir=$DIR/$tdir/${tfile}.d
local dir_restripe
local srv_uc=""
local rbac
local mdts=$(all_mdts_nodes)
(( MDS1_VERSION >= $(version_code v2_15_54-112-g22bef9b6c6) )) ||
skip "Need MDS >= 2.15.54.112 for role-based controls"
(( MDSCOUNT >= 2 )) || skip "mdt count $MDSCOUNT, skipping dne_ops role"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
dir_restripe=$(do_node $mds1_HOST \
"$LCTL get_param -n mdt.*MDT0000.enable_dir_restripe")
[ -n "$dir_restripe" ] || dir_restripe=0
do_nodes $mdts "$LCTL set_param mdt.*.enable_dir_restripe=1" ||
error "enabling dir_restripe failed"
stack_trap "do_nodes $mdts \
$LCTL set_param mdt.*.enable_dir_restripe=$dir_restripe"
rbac="dne_ops"
[[ -z "$srv_uc" ]] || rbac="$rbac,$srv_uc"
do_facet mgs \
"$LCTL nodemap_modify --name c0 --property rbac --value $rbac"||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
$LFS mkdir -i 0 ${testdir}_for_migr ||
error "$LFS mkdir ${testdir}_for_migr failed (1)"
touch ${testdir}_for_migr/file001 ||
error "touch ${testdir}_for_migr/file001 failed (1)"
$LFS mkdir -i 0 ${testdir}_mdt0 ||
error "$LFS mkdir ${testdir}_mdt0 failed (1)"
$LFS mkdir -i 1 ${testdir}_mdt1 ||
error "$LFS mkdir ${testdir}_mdt1 failed (1)"
set -vx
$LFS mkdir -i 1 $testdir || error "$LFS mkdir failed (1)"
rmdir $testdir
$LFS mkdir -c 2 $testdir || error "$LFS mkdir failed (2)"
rmdir $testdir
mkdir $testdir
$LFS setdirstripe -c 2 $testdir || error "$LFS setdirstripe failed"
rmdir $testdir
$LFS migrate -m 1 ${testdir}_for_migr || error "$LFS migrate failed"
touch ${testdir}_mdt0/fileA || error "touch fileA failed (1)"
mv ${testdir}_mdt0/fileA ${testdir}_mdt1/ || error "mv failed (1)"
set +vx
rm -rf ${testdir}*
$LFS mkdir -i 0 ${testdir}_for_migr ||
error "$LFS mkdir ${testdir}_for_migr failed (2)"
touch ${testdir}_for_migr/file001 ||
error "touch ${testdir}_for_migr/file001 failed (2)"
$LFS mkdir -i 0 ${testdir}_mdt0 ||
error "$LFS mkdir ${testdir}_mdt0 failed (2)"
$LFS mkdir -i 1 ${testdir}_mdt1 ||
error "$LFS mkdir ${testdir}_mdt1 failed (2)"
rbac="none"
if [[ -z "$srv_uc" ]]; then
rbac="none"
else
rbac="$srv_uc"
fi
do_facet mgs \
"$LCTL nodemap_modify --name c0 --property rbac --value $rbac"||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
set -vx
$LFS mkdir -i 1 $testdir && error "$LFS mkdir should fail (1)"
$LFS mkdir -c 2 $testdir && error "$LFS mkdir should fail (2)"
mkdir $testdir
$LFS setdirstripe -c 2 $testdir && error "$LFS setdirstripe should fail"
rmdir $testdir
$LFS migrate -m 1 ${testdir}_for_migr &&
error "$LFS migrate should fail"
touch ${testdir}_mdt0/fileA || error "touch fileA failed (2)"
mv ${testdir}_mdt0/fileA ${testdir}_mdt1/ || error "mv failed (2)"
set +vx
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
stack_trap cleanup_defaultnm_for_64
rbac="dne_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
set -vx
$LFS mkdir -i 1 $testdir ||
error "$LFS mkdir should succeed on default nodemap (1)"
rmdir $testdir
$LFS mkdir -c 2 $testdir ||
error "$LFS mkdir should succeed on default nodemap (2)"
rmdir $testdir
mkdir $testdir
$LFS setdirstripe -c 2 $testdir ||
error "$LFS setdirstripe should succeed on default nodemap"
rmdir $testdir
$LFS migrate -m 1 ${testdir}_for_migr ||
error "$LFS migrate should succeed on default nodemap"
$LFS migrate -m 0 ${testdir}_for_migr ||
error "$LFS migrate back should succeed on default nodemap"
set +vx
rbac="none"
[ -z "$srv_uc" ] || rbac="$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
set -vx
$LFS mkdir -i 1 $testdir &&
error "$LFS mkdir should fail on default nodemap (1)"
$LFS mkdir -c 2 $testdir &&
error "$LFS mkdir should fail on default nodemap (2)"
mkdir $testdir
$LFS setdirstripe -c 2 $testdir &&
error "$LFS setdirstripe should fail on default nodemap"
rmdir $testdir
$LFS migrate -m 1 ${testdir}_for_migr &&
error "$LFS migrate should fail on default nodemap"
set +vx
}
run_test 64b "Nodemap enforces dne_ops RBAC roles"
test_64c() {
local pool_quota=""
local lqa_quota=""
local lqa="lqa1"
local srv_uc=""
local rbac
(( MDS1_VERSION >= $(version_code v2_15_54-111-g971e025f5f) )) ||
skip "Need MDS >= 2.15.54.111 for role-based controls"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
(( MDS1_VERSION >= $(version_code v2_16_57-139-g8b2d38ee74) )) &&
pool_quota="pool_quota_ops"
(( MDS1_VERSION >= $(version_code v2_17_52-1-gedcf58d579) )) &&
lqa_quota="lqa_quota_ops"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
rbac="quota_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
[ -z "$pool_quota" ] || rbac="$rbac,$pool_quota"
[ -z "$lqa_quota" ] || rbac="$rbac,$lqa_quota"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value $rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
set -vx
$LFS setquota -u $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -u failed"
$LFS setquota -u $USER0 --delete $MOUNT
$LFS setquota -g $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -g failed"
$LFS setquota -g $USER0 --delete $MOUNT
$LFS setquota -p 1000 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -p failed"
$LFS setquota -p 1000 --delete $MOUNT
if [[ -n $pool_quota ]]; then
set +vx
create_pool $FSNAME.pool64c ||
error "create OST pool failed"
pool_add_targets pool64c 0 ||
error "add OSTs into pool failed"
set -vx
$LFS setquota -u $USER0 --pool pool64c -B 309200 $MOUNT ||
error "lfs setquota -u --pool failed (1)"
$LFS setquota -u $USER0 --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -u --pool failed (2)"
$LFS setquota -g $USER0 --pool pool64c -B 309200 $MOUNT ||
error "lfs setquota -g --pool failed (1)"
$LFS setquota -g $USER0 --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -g --pool failed (2)"
$LFS setquota -p 1000 --pool pool64c -B 309200 $MOUNT ||
error "lfs setquota -p --pool failed (1)"
$LFS setquota -p 1000 --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -p --pool failed (2)"
fi
$LFS setquota -U -b 10G -B 11G -i 100K -I 105K $MOUNT ||
error "lfs setquota -U failed"
$LFS setquota -U -b 0 -B 0 -i 0 -I 0 $MOUNT
$LFS setquota -G -b 10G -B 11G -i 100K -I 105K $MOUNT ||
error "lfs setquota -G failed"
$LFS setquota -G -b 0 -B 0 -i 0 -I 0 $MOUNT
$LFS setquota -P -b 10G -B 11G -i 100K -I 105K $MOUNT ||
error "lfs setquota -P failed"
$LFS setquota -P -b 0 -B 0 -i 0 -I 0 $MOUNT
$LFS setquota -u $USER0 -D $MOUNT ||
error "lfs setquota -u -D failed"
$LFS setquota -u $USER0 --delete $MOUNT
$LFS setquota -g $USER0 -D $MOUNT ||
error "lfs setquota -g -D failed"
$LFS setquota -g $USER0 --delete $MOUNT
$LFS setquota -p 1000 -D $MOUNT ||
error "lfs setquota -p -D failed"
$LFS setquota -p 1000 --delete $MOUNT
if [[ -n $pool_quota ]]; then
$LFS setquota -U --pool pool64c -B 11G $MOUNT ||
error "lfs setquota -U --pool failed (1)"
$LFS setquota -U --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -U --pool failed (2)"
$LFS setquota -G --pool pool64c -B 11G $MOUNT ||
error "lfs setquota -G --pool failed (1)"
$LFS setquota -G --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -G --pool failed (2)"
$LFS setquota -P --pool pool64c -B 11G $MOUNT ||
error "lfs setquota -P --pool failed (1)"
$LFS setquota -P --pool pool64c -B 0 $MOUNT ||
error "lfs setquota -P --pool failed (2)"
fi
if [[ -n $lqa_quota ]]; then
set +vx
do_facet mds1 $LCTL lqa new --fsname $FSNAME --name $lqa ||
error "cannot create $lqa"
stack_trap "do_facet mds1 $LCTL lqa destroy \
--fsname $FSNAME --name $lqa" EXIT
do_facet mds1 $LCTL lqa add --fsname $FSNAME \
--name $lqa --range $RUNAS_ID-$RUNAS_ID ||
error "cannot range $RUNAS_ID-$RUNAS_ID to $lqa"
set -vx
$LFS setquota -U --lqa $lqa -B 309200 $DIR ||
error "lfs setquota -U --lqa failed (1)"
$LFS setquota -U --lqa $lqa -B 0 $DIR ||
error "lfs setquota -U --lqa failed (2)"
$LFS setquota -G --lqa $lqa -B 309200 $DIR ||
error "lfs setquota -G --lqa failed (1)"
$LFS setquota -G --lqa $lqa -B 0 $DIR ||
error "lfs setquota -G --lqa failed (2)"
$LFS setquota -P --lqa $lqa -B 309200 $DIR ||
error "lfs setquota -P --lqa failed (1)"
$LFS setquota -P --lqa $lqa -B 0 $DIR ||
error "lfs setquota -P --lqa failed (2)"
fi
set +vx
rbac="none"
if [ -z "$srv_uc" ]; then
rbac="none"
else
rbac="$srv_uc"
fi
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
set -vx
$LFS setquota -u $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -u should fail"
$LFS setquota -u $USER0 --delete $MOUNT
$LFS setquota -g $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -g should fail"
$LFS setquota -g $USER0 --delete $MOUNT
$LFS setquota -p 1000 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -p should fail"
$LFS setquota -p 1000 --delete $MOUNT
if [[ -n $pool_quota ]]; then
$LFS setquota -u $USER0 --pool pool64c -B 309200 $MOUNT &&
error "lfs setquota -u --pool should fail"
$LFS setquota -g $USER0 --pool pool64c -B 309200 $MOUNT &&
error "lfs setquota -g --pool should fail"
$LFS setquota -p 1000 --pool pool64c -B 309200 $MOUNT &&
error "lfs setquota -p --pool should fail"
fi
$LFS setquota -U -b 10G -B 11G -i 100K -I 105K $MOUNT &&
error "lfs setquota -U should fail"
$LFS setquota -G -b 10G -B 11G -i 100K -I 105K $MOUNT &&
error "lfs setquota -G should fail"
$LFS setquota -P -b 10G -B 11G -i 100K -I 105K $MOUNT &&
error "lfs setquota -P should fail"
$LFS setquota -u $USER0 -D $MOUNT &&
error "lfs setquota -u -D should fail"
$LFS setquota -u $USER0 --delete $MOUNT
$LFS setquota -g $USER0 -D $MOUNT &&
error "lfs setquota -g -D should fail"
$LFS setquota -g $USER0 --delete $MOUNT
$LFS setquota -p 1000 -D $MOUNT &&
error "lfs setquota -p -D should fail"
$LFS setquota -p 1000 --delete $MOUNT
if [[ -n $pool_quota ]]; then
$LFS setquota -U --pool pool64c -B 11G $MOUNT &&
error "lfs setquota -U --pool should fail"
$LFS setquota -G --pool pool64c -B 11G $MOUNT &&
error "lfs setquota -G --pool should fail"
$LFS setquota -P --pool pool64c -B 11G $MOUNT &&
error "lfs setquota -P --pool should fail"
fi
if [[ -n $lqa_quota ]]; then
$LFS setquota -U --lqa $lqa -B 309200 $DIR &&
error "lfs setquota -U --lqa should fail"
$LFS setquota -G --lqa $lqa -B 309200 $DIR &&
error "lfs setquota -G --lqa should fail"
$LFS setquota -P --lqa $lqa -B 309200 $DIR &&
error "lfs setquota -P --lqa should fail"
fi
set +vx
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
stack_trap cleanup_defaultnm_for_64
rbac="quota_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
[ -z "$pool_quota" ] || rbac="$rbac,$pool_quota"
[ -z "$lqa_quota" ] || rbac="$rbac,$lqa_quota"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
set -vx
$LFS setquota -u $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -u failed on default nodemap"
$LFS setquota -u $USER0 --delete $MOUNT
$LFS setquota -g $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -g failed on default nodemap"
$LFS setquota -g $USER0 --delete $MOUNT
$LFS setquota -p 1000 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT ||
error "lfs setquota -p failed on default nodemap"
$LFS setquota -p 1000 --delete $MOUNT
set +vx
rbac="none"
[ -z "$srv_uc" ] || rbac="$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
set -vx
$LFS setquota -u $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -u should fail on default nodemap"
$LFS setquota -g $USER0 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -g should fail on default nodemap"
$LFS setquota -p 1000 -b 307200 -B 309200 -i 10000 -I 11000 $MOUNT &&
error "lfs setquota -p should fail on default nodemap"
set +vx
}
run_test 64c "Nodemap enforces quota related RBAC roles"
test_64d() {
local testfile=$DIR/$tdir/$tfile
local srv_uc=""
local rbac
local fid
(( MDS1_VERSION >= $(version_code 2.15.54) )) ||
skip "Need MDS >= 2.15.54 for role-based controls"
(( MDS1_VERSION >= $(version_code 2.16.50) )) &&
srv_uc="server_upcall"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
rbac="byfid_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value $rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
touch $testfile || error "touch $testfile failed (1)"
fid=$(lfs path2fid $testfile)
[[ -n "$fid" ]] || error "cannot get FID for $testfile (1)"
set -vx
$LFS fid2path $MOUNT $fid || error "fid2path $fid failed (1)"
cat $MOUNT/.lustre/fid/$fid || error "cat by fid failed"
lfs rmfid $MOUNT $fid || error "lfs rmfid failed"
set +vx
rbac="none"
if [ -z "$srv_uc" ]; then
rbac="none"
else
rbac="$srv_uc"
fi
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
touch $testfile || error "touch $testfile failed (2)"
fid=$(lfs path2fid $testfile)
[[ -n "$fid" ]] || error "cannot get FID for $testfile (1)"
set -vx
$LFS fid2path $MOUNT $fid || error "fid2path $fid failed (2)"
cat $MOUNT/.lustre/fid/$fid && error "cat by fid should fail"
lfs rmfid $MOUNT $fid && error "lfs rmfid should fail"
set +vx
rm -f $testfile
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
touch $testfile || error "touch $testfile failed (3)"
fid=$(lfs path2fid $testfile)
[[ -n "$fid" ]] || error "cannot get FID for $testfile (2)"
stack_trap cleanup_defaultnm_for_64
rbac="byfid_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
set -vx
$LFS fid2path $MOUNT $fid ||
error "fid2path $fid failed on default nodemap (1)"
cat $MOUNT/.lustre/fid/$fid ||
error "cat by fid failed on default nodemap"
lfs rmfid $MOUNT $fid || error "lfs rmfid failed on default nodemap"
set +vx
touch $testfile || error "touch $testfile failed (4)"
fid=$(lfs path2fid $testfile)
[[ -n "$fid" ]] || error "cannot get FID for $testfile (3)"
rbac="none"
[ -z "$srv_uc" ] || rbac="$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
set -vx
$LFS fid2path $MOUNT $fid ||
error "fid2path $fid failed on default nodemap (2)"
cat $MOUNT/.lustre/fid/$fid &&
error "cat by fid should fail on default nodemap"
lfs rmfid $MOUNT $fid &&
error "lfs rmfid should fail on default nodemap"
set +vx
}
run_test 64d "Nodemap enforces byfid_ops RBAC roles"
test_64e() {
local testfile=$DIR/$tdir/$tfile
local testdir=$DIR/$tdir/${tfile}.d
local srv_uc=""
local rbac
(( MDS1_VERSION >= $(version_code 2.15.54) )) ||
skip "Need MDS >= 2.15.54 for role-based controls"
(( MDS1_VERSION >= $(version_code 2.16.50) )) &&
srv_uc="server_upcall"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
# activate changelogs
changelog_register || error "changelog_register failed"
local cl_user="${CL_USERS[$SINGLEMDS]%% *}"
changelog_users $SINGLEMDS | grep -q $cl_user ||
error "User $cl_user not found in changelog_users"
changelog_chmask ALL
# do some IOs
mkdir $testdir || error "failed to mkdir $testdir"
touch $testfile || error "failed to touch $testfile"
rbac="chlg_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value $rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
# access changelogs
echo "changelogs dump"
changelog_dump || error "failed to dump changelogs"
echo "changelogs clear"
changelog_clear 0 || error "failed to clear changelogs"
rm -rf $testdir $testfile || error "rm -rf $testdir $testfile failed"
rbac="none"
if [ -z "$srv_uc" ]; then
rbac="none"
else
rbac="$srv_uc"
fi
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
# do some IOs
mkdir $testdir || error "failed to mkdir $testdir"
touch $testfile || error "failed to touch $testfile"
# access changelogs
echo "changelogs dump"
changelog_dump && error "dump changelogs should fail"
echo "changelogs clear"
changelog_clear 0 && error "clear changelogs should fail"
rm -rf $testdir $testfile
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value all ||
error "setting rbac all failed (3)"
wait_nm_sync c0 rbac
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
stack_trap cleanup_defaultnm_for_64
rbac="chlg_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
# do some IOs
mkdir $testdir || error "failed to mkdir $testdir on default nodemap"
touch $testfile || error "failed to touch $testfile on default nodemap"
# access changelogs
echo "changelogs dump on default nodemap"
changelog_dump || error "dump changelogs failed on default nodemap"
echo "changelogs clear on default nodemap"
changelog_clear 0 || error "clear changelogs failed on default nodemap"
rm -rf $testdir $testfile
rbac="none"
[ -z "$srv_uc" ] || rbac="$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
# do some IOs
mkdir $testdir || error "failed to mkdir $testdir on default nodemap"
touch $testfile || error "failed to touch $testfile on default nodemap"
# access changelogs
echo "changelogs dump on default nodemap"
changelog_dump && error "dump changelogs should fail on default nodemap"
echo "changelogs clear on default nodemap"
changelog_clear 0 &&
error "clear changelogs should fail on default nodemap"
rm -rf $testdir $testfile
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=all ||
error "setting rbac all on default failed (3)"
wait_nm_sync default rbac
}
run_test 64e "Nodemap enforces chlg_ops RBAC roles"
test_64f() {
local vaultdir=$DIR/$tdir/vault
local cli_enc
local policy
local protector
local srv_uc=""
local rbac
(( MDS1_VERSION >= $(version_code v2_15_54-112-g22bef9b6c6) )) ||
skip "Need MDS >= 2.15.54.112 for role-based controls"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
cli_enc=$($LCTL get_param mdc.*.import | grep client_encryption)
[ -n "$cli_enc" ] || skip "Need enc support, skip fscrypt_admin role"
which fscrypt || skip "Need fscrypt, skip fscrypt_admin role"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
echo "setup local client nodmap c0"
setup_local_client_nodemap "c0" 1 1
yes | fscrypt setup --force --verbose ||
echo "fscrypt global setup already done"
sed -i 's/\(.*\)policy_version\(.*\):\(.*\)\"[0-9]*\"\(.*\)/\1policy_version\2:\3"2"\4/' \
/etc/fscrypt.conf
yes | fscrypt setup --verbose $MOUNT ||
echo "fscrypt setup $MOUNT already done"
echo "fscrypt for mount $MOUNT is ready for use"
stack_trap "rm -rf $MOUNT/.fscrypt"
# file_perms is required because fscrypt uses chmod/chown
rbac="fscrypt_admin,file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (1)"
echo "waiting for nodemap file_perms and fscrypt to be modified"
wait_nm_sync c0 rbac
mkdir -p $vaultdir
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_64 $vaultdir ||
error "fscrypt encrypt $vaultdir failed"
fscrypt lock $vaultdir || error "fscrypt lock $vaultdir failed (1)"
echo "$vaultdir is locked away with encryption"
policy=$(fscrypt status $vaultdir | awk '$1 == "Policy:"{print $2}')
[ -n "$policy" ] || error "could not get enc policy"
echo "fscrypt policy $policy is ready"
protector=$(fscrypt status $vaultdir |
awk 'BEGIN {found=0} { if (found == 1) { print $1 }} \
$1 == "PROTECTOR" {found=1}')
[ -n "$protector" ] || error "could not get enc protector"
set +vx
cancel_lru_locks
# file_perms is required because fscrypt uses chmod/chown
rbac="file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
set -vx
echo mypass | fscrypt unlock $vaultdir ||
error "fscrypt unlock $vaultdir failed"
fscrypt lock $vaultdir || error "fscrypt lock $vaultdir failed (2)"
fscrypt metadata destroy --protector=$MOUNT:$protector --force &&
error "destroy protector should fail"
fscrypt metadata destroy --policy=$MOUNT:$policy --force &&
error "destroy policy should fail"
mkdir -p ${vaultdir}2
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase \
--name=protector_64bis ${vaultdir}2 &&
error "fscrypt encrypt ${vaultdir}2 should fail"
set +vx
cancel_lru_locks
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value all ||
error "setting rbac all failed (3)"
wait_nm_sync c0 rbac
set -vx
fscrypt metadata destroy --protector=$MOUNT:$protector --force ||
error "destroy protector failed"
fscrypt metadata destroy --policy=$MOUNT:$policy --force ||
error "destroy policy failed"
set +vx
rm -rf ${vaultdir}*
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
stack_trap cleanup_defaultnm_for_64
rbac="fscrypt_admin,file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
mkdir -p $vaultdir || error "mkdir $vaultdir failed on default nodemap"
set -vx
echo -e 'mypass\nmypass' | fscrypt encrypt --source=custom_passphrase \
--name=protector64f $vaultdir ||
error "encrypt $vaultdir failed on default nodemap"
fscrypt lock $vaultdir ||
error "fscrypt lock $vaultdir on default failed (1)"
policy=$(fscrypt status $vaultdir | awk '$1 == "Policy:"{print $2}')
echo "$vaultdir is locked away with encryption"
[ -n "$policy" ] || error "could not get enc policy"
echo "fscrypt policy $policy is ready"
protector=$(fscrypt status $vaultdir |
awk 'BEGIN {found=0} { if (found == 1) { print $1 }} \
$1 == "PROTECTOR" {found=1}')
[ -n "$protector" ] || error "could not get enc protector"
set +vx
cancel_lru_locks
rbac="file_perms"
[ -z "$srv_uc" ] || rbac="$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
set -vx
echo mypass | fscrypt unlock $vaultdir ||
error "unlock $vaultdir failed on default nodemap"
fscrypt lock $vaultdir ||
error "fscrypt lock $vaultdir failed on default (2)"
fscrypt metadata destroy --protector=$MOUNT:$protector --force &&
error "destroy protector should fail on default"
fscrypt metadata destroy --policy=$MOUNT:$policy --force &&
error "destroy policy should fail on default"
mkdir -p ${vaultdir}2
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase \
--name=protector_64fbis ${vaultdir}2 &&
error "fscrypt encrypt ${vaultdir}2 should fail on def"
set +vx
cancel_lru_locks
do_facet mgs $LCTL nodemap_modify --name default --property rbac=all ||
error "setting rbac $rbac on default nodemap failed (3)"
wait_nm_sync default rbac
set -vx
fscrypt metadata destroy --protector=$MOUNT:$protector --force ||
error "destroy protector failed"
fscrypt metadata destroy --policy=$MOUNT:$policy --force ||
error "destroy policy failed"
set +vx
rm -rf ${vaultdir}*
}
run_test 64f "Nodemap enforces fscrypt_admin RBAC roles"
test_64g() {
local testfile=$DIR/$tdir/$tfile
local mdts=$(all_mdts_nodes)
(( MDS1_VERSION >= $(version_code 2.16.51) )) ||
skip "Need MDS >= 2.16.51 for role-based controls"
# Add groups, and client to new group, on client only.
# Server is not aware.
groupadd -g 5000 grptest64g1
stack_trap "groupdel grptest64g1" EXIT
groupadd -g 5001 grptest64g2
stack_trap "groupdel grptest64g2" EXIT
groupadd -g 5002 grptest64g3
stack_trap "groupdel grptest64g3" EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
chmod 750 $DIR/$tdir
chgrp grptest64g1 $DIR/$tdir
echo hi > $DIR/$tdir/fileA
chmod 640 $DIR/$tdir/fileA
chgrp grptest64g3 $DIR/$tdir/fileA
setfacl -m g:grptest64g2:r $DIR/$tdir/fileA
setfacl -m g:grptest64g2:rwx $DIR/$tdir
ls -lR $DIR/$tdir
setup_local_client_nodemap "c0" 1 1
stack_trap cleanup_local_client_nodemap EXIT
# remove server_upcall from rbac roles,
# to make this client use INTERNAL upcall
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value file_perms ||
error "setting rbac file_perms failed"
wait_nm_sync c0 rbac
$RUNAS touch $DIR/$tdir/fileB &&
error "touch $DIR/$tdir/fileB should fail"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5001 touch $DIR/$tdir/fileB ||
error "touch $DIR/$tdir/fileB failed"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5000,5001 touch $DIR/$tdir/fileC ||
error "touch $DIR/$tdir/fileC failed"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS cat $DIR/$tdir/fileA && error "cat $DIR/$tdir/fileA should fail"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5000,5001 cat $DIR/$tdir/fileA ||
error "cat $DIR/$tdir/fileA failed"
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
stack_trap cleanup_defaultnm_for_64
# remove server_upcall from rbac roles,
# to make this client use INTERNAL upcall
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=file_perms ||
error "setting rbac file_perms failed"
wait_nm_sync default rbac
$RUNAS touch $DIR/$tdir/fileB &&
error "touch $DIR/$tdir/fileB should fail on default"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5001 touch $DIR/$tdir/fileB ||
error "touch $DIR/$tdir/fileB failed on default"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5000,5001 touch $DIR/$tdir/fileC ||
error "touch $DIR/$tdir/fileC failed on default"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS cat $DIR/$tdir/fileA &&
error "cat $DIR/$tdir/fileA should fail on default"
do_nodes $mdts "$LCTL set_param mdt.*.identity_int_flush=$RUNAS_ID"
$RUNAS -G 5000,5001 cat $DIR/$tdir/fileA ||
error "cat $DIR/$tdir/fileA failed on default"
}
run_test 64g "Nodemap enforces server_upcall RBAC role"
test_64h() {
local testfile=$DIR/$tdir/$tfile
local offset_start=100000
local offset_limit=200000
local projid=1001
local srv_uc=""
local rbac
local fid
(( MDS1_VERSION >= $(version_code v2_15_54-112-g22bef9b6c6) )) ||
skip "Need MDS >= 2.15.54.112 for role-based controls"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
do_nodes $(all_mdts_nodes) "$LCTL set_param mdt.*.identity_upcall=NONE"
stack_trap \
"$LFS setquota -p $((projid+offset_start)) --delete $DIR/$tdir" EXIT
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
chmod 777 $DIR/$tdir
$LFS project -p $((projid+offset_start)) -s $DIR/$tdir
$LFS setquota -p $((projid+offset_start)) -b 1G -B 1G $DIR/$tdir
$LFS project -d $DIR/$tdir
$LFS quota -aph $DIR/$tdir
setup_local_client_nodemap "c0" 1 1
# skip test if server does not support local_admin rbac role
rbac=$(do_facet mds $LCTL get_param -n nodemap.c0.rbac)
[[ "$rbac" =~ "local_admin" ]] ||
skip "server does not support 'local_admin' rbac role"
# Let's offset ids. Even root is offset.
do_facet mgs $LCTL nodemap_add_offset --name c0 \
--offset $offset_start --limit $offset_limit ||
error "cannot set offset for c0"
# projid_set is required for 'lfs project'
rbac="projid_set,file_perms,quota_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
$RUNAS touch $testfile
# Without local_admin, root capabilities are dropped
chmod o+x $testfile && error "root chmod should fail (1)"
# and setquota/lfs project is not permitted
$LFS setquota -p $projid -b 4G -B 4G $DIR/$tdir &&
error "setquota should fail (1)"
$LFS project -p $((projid+1)) -s $DIR/$tdir &&
error "setting projid should fail (1)"
rbac="projid_set,file_perms,quota_ops,local_admin"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property rbac --value $rbac ||
error "setting rbac $rbac failed (2)"
# squash root by setting admin=0
do_facet mgs $LCTL nodemap_modify --name c0 \
--property admin --value 0
wait_nm_sync c0 admin_nodemap
# Even with local_admin, capabilities are dropped if root is squashed
chmod o+x $testfile && error "root chmod should fail (2)"
# and setquota/lfs project is not permitted
$LFS setquota -p $projid -b 4G -B 4G $DIR/$tdir &&
error "setquota should fail (2)"
$LFS project -p $((projid+1)) -s $DIR/$tdir &&
error "setting projid should fail (2)"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property admin --value 1
wait_nm_sync c0 admin_nodemap
# with local_admin and admin=1, capabilities are kept
chmod o+x $testfile || error "root chmod failed (1)"
# and setquota/lfs project is permitted
$LFS setquota -p $projid -b 4G -B 4G $DIR/$tdir ||
error "setquota failed (1)"
$LFS project -p $((projid+1)) -s $DIR/$tdir ||
error "setting projid failed (1)"
# remove offset and local_admin but keep admin, so that root
# on client is root on file system side
do_facet mgs $LCTL nodemap_del_offset --name c0 ||
error "cannot del offset for c0"
rbac="projid_set,file_perms,quota_ops"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac ||
error "setting rbac $rbac failed (3)"
wait_nm_sync c0 rbac
# as root, capabilities are kept even without local_admin
chmod g+x $testfile || error "root chmod failed (2)"
# and setquota/lfs project is permitted
$LFS setquota -p $((projid+offset_start)) -b 3G -B 3G $DIR/$tdir ||
error "setquota failed (2)"
$LFS project -p $((projid+offset_start)) -s $DIR/$tdir ||
error "setting projid failed (2)"
}
run_test 64h "Nodemap enforces local_admin RBAC roles"
test_64i() {
local tf=$DIR/$tdir/$tfile
local offset_start=100000
local offset_limit=100000
local quota_limit=10 # MB
local dom_size=20971520 # 20MB
local rbac
local stat
(( OST1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need OST >= 2.17.50 for this test"
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS >= 2.17.50 for this test"
do_nodes $(all_mdts_nodes) \
$LCTL set_param mdt.*.identity_upcall=NONE
# Increase dom_stripesize to easier exceed quota_limit for DOM files
local dom_saved=$(do_facet mds1 $LCTL get_param -n \
lod.*-MDT0000-mdtlov.dom_stripesize)
do_nodes $(all_mdts_nodes) $LCTL set_param -n \
lod.*-MDT*-mdtlov.dom_stripesize=$dom_size ||
error "set dom_stripesize failed"
stack_trap "do_nodes $(all_mdts_nodes) $LCTL set_param -n \
lod.*-MDT*-mdtlov.dom_stripesize=$dom_saved"
stack_trap "$LFS setquota -u $offset_start --delete $MOUNT"
stack_trap cleanup_local_client_nodemap_with_mounts
mkdir -p ${DIR}/$tdir || error "mkdir ${DIR}/$tdir failed"
chown $offset_start ${DIR}/$tdir
setup_local_client_nodemap "c0" 1 1
# Enable quota enforcement for both OST and MDT including block
# quota on MDT for DOM files (see quota_slave_dt)
stack_trap "set_ost_qtype none"
set_ost_qtype "u" || error "enable ost quota failed"
stack_trap "set_mdt_qtype none"
set_mdt_qtype "u" || error "enable mdt quota failed"
do_nodes $(all_mdts_nodes) $LCTL set_param \
osd-*.*-MDT*.quota_slave_dt.enabled=u ||
error "enable mdt block quota failed"
stack_trap "do_nodes $(all_mdts_nodes) $LCTL set_param \
osd-*.*-MDT*.quota_slave_dt.enabled=none"
# Set quota limit on the mapped root UID (offset_start)
$LFS setquota -u $offset_start -b 0 -B ${quota_limit}M \
-i 0 -I 0 $MOUNT || error "set quota failed"
echo "Current MOUNT:"
ls -al $MOUNT
do_facet mgs $LCTL nodemap_add_offset --name c0 \
--offset $offset_start --limit $offset_limit ||
error "cannot set offset for c0"
wait_nm_sync c0 offset
echo "Current MOUNT:"
ls -al $MOUNT
echo "Test 1: admin_nodemap=1, local_admin in RBAC, trusted=1"
echo " Expected: root can bypass quota (write succeeds)"
rbac="file_perms,quota_ops,local_admin,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
# Write should succeed (bypass quota)
$DD of=$tf bs=1M count=$((quota_limit + 5)) oflag=direct ||
error "write failed, expected success (local_admin)"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 2: admin_nodemap=1, local_admin NOT in RBAC, trusted=1"
echo " Expected: root must respect quota (write fails with EDQUOT)"
rbac="file_perms,quota_ops,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
# Write should fail (quota enforced)
stat=$(LOCALE=C $DD of=$tf bs=1M \
count=$((quota_limit + 5)) oflag=direct 2>&1)
echo "dd output: $stat"
echo "$stat" | grep -q "Disk quota exceeded" ||
error "expected 'Disk quota exceeded' but got: $stat"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 3: admin_nodemap=1, local_admin NOT in RBAC, trusted=0"
echo " Expected: root must respect quota (write fails with EDQUOT)"
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted \
--value 0 || error "setting trusted=0 failed"
wait_nm_sync c0 trusted_nodemap
# Write should fail (quota enforced, trusted doesn't affect this)
stat=$(LOCALE=C $DD of=$tf bs=1M \
count=$((quota_limit + 5)) oflag=direct 2>&1)
echo "dd output: $stat"
echo "$stat" | grep -q "Disk quota exceeded" ||
error "expected 'Disk quota exceeded' but got: $stat"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 4: admin_nodemap=1, local_admin in RBAC, trusted=0"
echo " Expected: root can bypass quota (write succeeds)"
rbac="file_perms,quota_ops,local_admin,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
# Write should succeed (bypass quota, trusted doesn't affect this)
$DD of=$tf bs=1M count=$((quota_limit + 5)) oflag=direct ||
error "write failed, expected success (local_admin)"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 5: admin_nodemap=0, local_admin in RBAC"
echo " Expected: root is squashed, permission denied"
do_facet mgs $LCTL nodemap_modify --name c0 --property admin \
--value 0 || error "setting admin=0 failed"
wait_nm_sync c0 admin_nodemap
echo "Current MOUNT:"
ls -al $MOUNT
# Write should fail (root is squashed, quota enforced)
stat=$(LOCALE=C $DD of=$tf bs=1M \
count=$((quota_limit + 5)) oflag=direct 2>&1)
echo "dd output: $stat"
echo "$stat" | grep -q "Permission denied" ||
error "expected 'Permission denied' but got: $stat"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 6: admin_nodemap=0, local_admin NOT in RBAC"
echo " Expected: root is squashed, permission denied"
rbac="file_perms,quota_ops,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
# Write should fail (root is squashed, quota enforced)
stat=$(LOCALE=C $DD of=$tf bs=1M \
count=$((quota_limit + 5)) oflag=direct 2>&1)
echo "dd output: $stat"
echo "$stat" | grep -q "Permission denied" ||
error "expected 'Permission denied' but got: $stat"
# Restore admin=1, trusted=1 for DOM tests
do_facet mgs $LCTL nodemap_modify --name c0 --property admin \
--value 1 || error "setting admin=1 failed"
do_facet mgs $LCTL nodemap_modify --name c0 --property trusted \
--value 1 || error "setting trusted=1 failed"
wait_nm_sync c0 trusted_nodemap
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 7: admin=1, trusted=1, local_admin in RBAC (DOM only)"
echo " Expected: root can bypass quota (DOM write succeeds)"
rbac="file_perms,quota_ops,local_admin,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
$LFS setstripe -E $dom_size -L mdt $tf ||
error "setstripe DOM failed"
$DD of=$tf bs=1M count=$((quota_limit + 5)) oflag=sync ||
error "DOM write failed, expected success (local_admin)"
rm -f $tf
wait_delete_completed || error "wait_delete_completed failed"
echo "Test 8: admin=1, trusted=1, local_admin NOT in RBAC (DOM only)"
echo " Expected: root must respect quota (DOM write fails EDQUOT)"
rbac="file_perms,quota_ops,server_upcall"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac \
--value $rbac || error "setting rbac $rbac failed"
wait_nm_sync c0 rbac
$LFS setstripe -E $dom_size -L mdt $tf ||
error "setstripe DOM failed"
stat=$(LOCALE=C $DD of=$tf bs=1M \
count=$((quota_limit + 5)) oflag=sync 2>&1)
echo "dd DOM output: $stat"
echo "$stat" | grep -q "Disk quota exceeded" ||
error "expected DOM 'Disk quota exceeded' but got: $stat"
}
run_test 64i "Nodemap quota enforcement with local_admin RBAC and offsets"
test_64j() {
local testfile=$DIR/$tdir/$tfile
local testdir=$DIR/$tdir/${tfile}.d
local projid=1001
local srv_uc=""
local rbac
(( MDS1_VERSION >= $(version_code 2.17.52) )) ||
skip "Need MDS >= 2.17.50 for projid_set RBAC role"
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
stack_trap cleanup_local_client_nodemap EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
setup_local_client_nodemap "c0" 1 1
# projid_set role present - should allow project ID changes
rbac="file_perms,projid_set"
[[ -z "$srv_uc" ]] || rbac+=",$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac=$rbac ||
error "setting rbac $rbac failed (1)"
wait_nm_sync c0 rbac
touch $testfile || error "failed to touch $testfile"
mkdir $testdir || error "failed to mkdir $testdir"
$LFS project -p $projid $testfile ||
error "lfs project failed with projid_set role"
$LFS project -p $projid -s $testdir ||
error "lfs project -s failed with projid_set role"
local file_projid=$($LFS project $testfile | awk '{print $1}')
local dir_projid=$($LFS project -d $testdir | awk '{print $1}')
(( file_projid == projid )) ||
error "expected file projid $projid, got $file_projid (1)"
(( dir_projid == projid )) ||
error "expected dir projid $projid, got $dir_projid (1)"
# projid_set role absent - should deny project ID changes
rbac="file_perms"
[[ -z "$srv_uc" ]] || rbac+=",$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac=$rbac ||
error "setting rbac $rbac failed (2)"
wait_nm_sync c0 rbac
$LFS project -p $((projid+1)) $testfile &&
error "lfs project should fail without projid_set role"
$LFS project -p $((projid+1)) -s $testdir &&
error "lfs project -s should fail without projid_set role"
file_projid=$($LFS project $testfile | awk '{print $1}')
dir_projid=$($LFS project -d $testdir | awk '{print $1}')
(( file_projid == projid )) ||
error "expected file projid $projid, got $file_projid (2)"
(( dir_projid == projid )) ||
error "expected dir projid $projid, got $dir_projid (2)"
$LFS project -C $testfile &&
error "lfs project -C $testfile should fail without projid_set role"
$LFS project -C $testdir &&
error "lfs project -C $testdir should fail without projid_set role"
# Restore projid_set role and clear project ID - should succeed
rbac="file_perms,projid_set"
[[ -z "$srv_uc" ]] || rbac+=",$srv_uc"
do_facet mgs $LCTL nodemap_modify --name c0 --property rbac=$rbac ||
error "setting rbac $rbac failed (3)"
wait_nm_sync c0 rbac
$LFS project -C $testfile ||
error "lfs project -C $testfile failed with projid_set role"
$LFS project -C $testdir ||
error "lfs project -C $testdir failed with projid_set role"
file_projid=$($LFS project $testfile | awk '{print $1}')
dir_projid=$($LFS project -d $testdir | awk '{print $1}')
(( file_projid == 0 )) ||
error "expected file projid 0, got $file_projid (3)"
(( dir_projid == 0 )) ||
error "expected dir projid 0, got $dir_projid (3)"
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
# Now test rbac on default nodemap
setup_defaultnm_for_64
touch $testfile
mkdir $testdir
stack_trap cleanup_defaultnm_for_64
# projid_set role present - should allow project ID changes
rbac="file_perms,projid_set"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (1)"
wait_nm_sync default rbac
$LFS project -p $projid $testfile ||
error "setting file projid failed on default nodemap (1)"
$LFS project -p $projid -s $testdir ||
error "setting dir projid failed on default nodemap (1)"
file_projid=$($LFS project $testfile | awk '{print $1}')
dir_projid=$($LFS project -d $testdir | awk '{print $1}')
[ "$file_projid" = "$projid" ] ||
error "expect file projid $projid, got $file_projid on def (1)"
[ "$dir_projid" = "$projid" ] ||
error "expect dir projid $projid, got $dir_projid on def (1)"
# projid_set role absent - should deny project ID changes
rbac="file_perms"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac on default nodemap failed (2)"
wait_nm_sync default rbac
$LFS project -p $((projid+1)) $testfile &&
error "setting file projid should fail on default nodemap"
$LFS project -p $((projid+1)) -s $testdir &&
error "setting dir projid should fail on default nodemap"
file_projid=$($LFS project $testfile | awk '{print $1}')
dir_projid=$($LFS project -d $testdir | awk '{print $1}')
[ "$file_projid" = "$projid" ] ||
error "expect file projid $projid, got $file_projid on def (2)"
[ "$dir_projid" = "$projid" ] ||
error "expect dir projid $projid, got $dir_projid on def (2)"
$LFS project -C $testfile &&
error "clearing projid should fail without projid_set role (1)"
$LFS project -C $testdir &&
error "clearing projid should fail without projid_set role (2)"
# Restore projid_set role and clear project ID - should succeed
rbac="file_perms,projid_set"
[ -z "$srv_uc" ] || rbac="$rbac,$srv_uc"
do_facet mgs $LCTL nodemap_modify --name default \
--property rbac=$rbac ||
error "setting rbac $rbac failed on default (3)"
wait_nm_sync default rbac
$LFS project -C $testfile ||
error "clearing projid failed with projid_set role (1)"
$LFS project -C $testdir ||
error "clearing projid failed with projid_set role (2)"
file_projid=$($LFS project $testfile | awk '{print $1}')
dir_projid=$($LFS project -d $testdir | awk '{print $1}')
[ "$file_projid" = "0" ] ||
error "expected file projid $projid, got $file_projid (3)"
[ "$dir_projid" = "0" ] ||
error "expected dir projid $projid, got $dir_projid (3)"
}
run_test 64j "Nodemap enforces projid_set RBAC role"
test_64k() {
(( MDS1_VERSION >= $(version_code 2.17.52-4) )) ||
skip "Need MDS >= 2.17.52.4 for foreign_ops RBAC role"
local param=mdt.$FSNAME-*.enable_foreign_dir
local param_gid=${param}_gid
local foreign_old=($(do_facet mds1 $LCTL get_param -n $param))
local foreign_gid_old=($(do_facet mds1 $LCTL get_param -n $param_gid))
local foreign_magic="lmv_foreign_magic:.*cd50cd0"
local uuid1=$(sysctl -n kernel.random.uuid)
local testdir=$DIR/$tdir
local srv_uc=""
local rbac
local prop
(( MDS1_VERSION >= $(version_code v2_16_50-98-g3b04d6ac1d) )) &&
srv_uc="server_upcall"
stack_trap cleanup_local_client_nodemap
setup_local_client_nodemap "c0" 1 1
mkdir_on_mdt0 -o 777 $testdir
# enable foreign directory ops for everyone (should be the default)
# assume basic foreign_dir create is working due to sanity test_27Ke
do_facet mds1 "$LCTL set_param $param=1 $param_gid=-1" ||
error "setting $param=1 $param_gid=-1"
stack_trap "do_facet mds1 \
$LCTL set_param $param=$foreign_old $param_gid=$foreign_gid_old"
# test with RBAC foreign_ops *disabled* should *fail* for everyone
rbac=${srv_uc:-"none"}
do_facet mgs "$LCTL nodemap_modify --name c0 --property rbac=$rbac" ||
error "disabling rbac=$rbac failed"
wait_nm_sync c0 rbac
prop=$(do_facet mds1 "$LCTL nodemap_info --name c0 --property rbac")
[[ "$prop" =~ $rbac ]] || error "$prop, missing $rbac"
create_foreign_dir -d $testdir/$tdir-0 -x "$uuid1" -t 1 &&
error "foreign_dir succeeded for root with rbac=$rbac"
[[ ! -e $testdir/$tdir-0 ]] ||
error "$tdir-0 created for root with rbac=$rbac"
$RUNAS create_foreign_dir -d $testdir/$tdir-gid-0u -x $uuid1 -t 1 &&
error "foreign_dir succeeded for user with rbac=$rbac"
[[ ! -e $testdir/$tdir-0u ]] ||
error "$tdir-0u created for user with rbac=$rbac"
# test with RBAC foreign_ops *enabled*, should *work* for everyone
rbac="foreign_ops"
[[ -z "$srv_uc" ]] || rbac+=",$srv_uc"
do_facet mgs "$LCTL nodemap_modify --name c0 --property rbac=$rbac" ||
error "enabling rbac=$rbac failed"
wait_nm_sync c0 rbac
prop=$(do_facet mds1 "$LCTL nodemap_info --name c0 --property rbac")
[[ "$prop" =~ "foreign_ops" ]] || error "$prop, missing 'foreign_ops'"
create_foreign_dir -d $testdir/$tdir-1 -x "$uuid1" -t 1 ||
error "foreign_dir failed for root with rbac=$rbac"
parse_foreign_dir -d $testdir/$tdir-1 | grep "$foreign_magic" ||
error "$testdir/$tdir-1: invalid LMV EA magic for -1"
$RUNAS create_foreign_dir -d $testdir/$tdir-gid-1u -x $uuid1 -t 1 ||
error "foreign_dir failed for user with rbac=$rbac"
parse_foreign_dir -d $testdir/$tdir-gid-1u | grep "$foreign_magic" ||
error "$testdir/$tdir-gid-1u: invalid LMV EA magic for -gid-1u"
# test with foreign_ops *enabled*, globally *disabled* should *fail*
do_facet mds1 "$LCTL set_param $param=0" || error "setting $param=0"
create_foreign_dir -d $testdir/$tdir-gd -x "$uuid1" -t 1 &&
error "foreign_dir succeeded for root with $param=0 rbac=$rbac"
[[ ! -e $testdir/$tdir-gd ]] ||
error "$tdir-gd created for root with $param=0 rbac=$rbac"
}
run_test 64k "Nodemap enforces foreign_ops RBAC roles"
test_64l() {
local t_with=$DIR/$tdir/$tfile.with_immutable_flags
local t_without=$DIR/$tdir/$tfile.without_immutable_flags
local rbac
local flag
(( MDS1_VERSION >= $(version_code 2.17.53) )) ||
skip "Need MDS >= 2.17.53 for immutable_flags RBAC role"
# Probe default nodemap before setup: rbac property (LU-19975) and
# immutable_flags role support, to avoid costly nodemap configuration.
do_facet mgs $LCTL get_param -n nodemap.default.rbac ||
skip "server does not support rbac on default nodemap"
rbac=$(do_facet mgs $LCTL get_param -n nodemap.default.rbac)
[[ "$rbac" =~ "immutable_flags" ]] ||
skip "server does not support 'immutable_flags' rbac role"
stack_trap cleanup_local_client_nodemap EXIT
rm -rf "$DIR/$tdir"
stack_trap "chattr -i -a $t_with $t_without 2>/dev/null || true; \
rm -rf $DIR/$tdir" EXIT
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
touch $t_with $t_without || error "touch $t_with $t_without failed"
setup_local_client_nodemap "c0" 1 1
# Verify c0 nodemap has immutable_flags (inherited from default).
rbac=$(do_facet mgs $LCTL get_param -n nodemap.c0.rbac)
[[ "$rbac" =~ "immutable_flags" ]] ||
error "c0 nodemap does not have 'immutable_flags' rbac role"
# +/-i/a should succeed with the role present. Re-apply each flag on
# t_with afterwards so both flags remain set for the deny test below
# (RBAC is only checked when the flag changes).
for flag in i a; do
chattr +$flag $t_with ||
error "(0) chattr +$flag failed with immutable_flags"
chattr -$flag $t_with ||
error "(1) chattr -$flag failed with immutable_flags"
chattr +$flag $t_with ||
error "(2) chattr +$flag failed with immutable_flags"
done
# immutable_flags absent: +flag on a clean file (t_without) and -flag on
# t_with (flags preloaded above) should both fail, even for root.
stack_trap 'set_nodemap_rbac c0 "file_perms,immutable_flags"' EXIT
set_nodemap_rbac c0 "file_perms"
for flag in i a; do
chattr +$flag $t_without &&
error "(3) chattr +$flag should fail w/o immutable_flags"
chattr -$flag $t_with &&
error "(4) chattr -$flag should fail w/o immutable_flags"
done
return 0
}
run_test 64l "Nodemap enforces immutable_flags RBAC role"
look_for_files() {
local pattern=$1
local neg=$2
local path=$3
local expected=$4
local res
(( neg == 1 )) || neg=""
$LFS find -type f ${neg:+"!"} --attrs $pattern $path > $TMP/res
cat $TMP/res
res=$(cat $TMP/res | wc -l)
(( res == $expected )) ||
error "Find $pattern $path: found $res, expected $expected"
}
test_65() {
local dirbis=$DIR/${tdir}_bis
local testfile=$DIR/$tdir/$tfile
local res
$LCTL get_param mdc.*.import | grep -q client_encryption ||
skip "client encryption not supported"
mount.lustre --help |& grep -q "test_dummy_encryption:" ||
skip "need dummy encryption support"
# $dirbis is not going to be encrypted, as client
# is not mounted with -o test_dummy_encryption yet
mkdir $dirbis
stack_trap "rm -rf $dirbis" EXIT
touch $dirbis/$tfile.1
touch $dirbis/$tfile.2
chattr +i $dirbis/$tfile.2
stack_trap "chattr -i $dirbis/$tfile.2" EXIT
stack_trap cleanup_for_enc_tests EXIT
setup_for_enc_tests
# All files/dirs under $DIR/$tdir are encrypted
touch $testfile.1
touch $testfile.2
chattr +i $testfile.2
stack_trap "chattr -i $testfile.2" EXIT
$LFS find -printf "%p %LA\n" $dirbis/$tfile.1
res=$($LFS find -printf "%LA" $dirbis/$tfile.1)
[ "$res" == "---" ] ||
error "$dirbis/$tfile.1 should have no attr, showed $res (1)"
$LFS find -printf "%p %La\n" $dirbis/$tfile.1
res=$($LFS find -printf "%La" $dirbis/$tfile.1)
[ "$res" == "---" ] ||
error "$dirbis/$tfile.1 should have no attr, showed $res (2)"
$LFS find -printf "%p %LA\n" $dirbis/$tfile.2
res=$($LFS find -printf "%LA" $dirbis/$tfile.2)
[ "$res" == "Immutable" ] ||
error "$dirbis/$tfile.2 should be Immutable, showed $res"
$LFS find -printf "%p %La\n" $dirbis/$tfile.2
res=$($LFS find -printf "%La" $dirbis/$tfile.2)
[ "$res" == "i" ] ||
error "$dirbis/$tfile.2 should be 'i', showed $res"
$LFS find -printf "%p %LA\n" $testfile.1
res=$($LFS find -printf "%LA" $testfile.1)
[ "$res" == "Encrypted" ] ||
error "$testfile.1 should be Encrypted, showed $res"
$LFS find -printf "%p %La\n" $testfile.1
res=$($LFS find -printf "%La" $testfile.1)
[ "$res" == "E" ] ||
error "$testfile.1 should be 'E', showed $res"
$LFS find -printf "%p %LA\n" $testfile.2
res=$($LFS find -printf "%LA" $testfile.2)
[ "$res" == "Immutable,Encrypted" ] ||
error "$testfile.2 should be Immutable,Encrypted, showed $res"
$LFS find -printf "%p %La\n" $testfile.2
res=$($LFS find -printf "%La" $testfile.2)
[ "$res" == "iE" ] ||
error "$testfile.2 should be 'iE', showed $res"
echo Expecting to find 2 encrypted files
look_for_files Encrypted 0 "$DIR/${tdir}*" 2
echo Expecting to find 2 encrypted files
look_for_files E 0 "$DIR/${tdir}*" 2
echo Expecting to find 2 non-encrypted files
look_for_files Encrypted 1 "$DIR/${tdir}*" 2
echo Expecting to find 2 non-encrypted files
look_for_files E 1 "$DIR/${tdir}*" 2
echo Expecting to find 1 encrypted+immutable file
look_for_files "Encrypted,Immutable" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 encrypted+immutable file
look_for_files "Ei" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 encrypted+^immutable file
look_for_files "Encrypted,^Immutable" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 encrypted+^immutable file
look_for_files "E^i" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 ^encrypted+immutable file
look_for_files "^Encrypted,Immutable" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 ^encrypted+immutable file
look_for_files "^Ei" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 ^encrypted+^immutable file
look_for_files "^Encrypted,^Immutable" 0 "$DIR/${tdir}*" 1
echo Expecting to find 1 ^encrypted+^immutable file
look_for_files "^E^i" 0 "$DIR/${tdir}*" 1
}
run_test 65 "lfs find -printf %La and --attrs support"
cleanup_68() {
lctl set_param fail_loc=0 fail_val=0
mount_client $MOUNT ${MOUNT_OPTS} || error "re-mount $MOUNT failed"
if is_mounted $MOUNT2; then
mount_client $MOUNT2 ${MOUNT_OPTS} ||
error "re-mount $MOUNT2 failed"
fi
}
test_68() {
stack_trap cleanup_68 EXIT
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
#define CFS_FAIL_ONCE|OBD_FAIL_PTLRPC_DROP_MGS 0x51d
lctl set_param fail_loc=0x8000051d fail_val=20
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "mount failed"
umount_client $MOUNT || error "re-umount $MOUNT failed"
}
run_test 68 "all config logs are processed"
test_69() {
local mdt="$(mdtname_from_index 0 $MOUNT)"
local param
local orig
(( MDS1_VERSION >= $(version_code v2_15_61-210-g2153e86541) )) ||
skip "need MDS >= 2.15.61.210 for upcall sanity checking"
param="mdt.$mdt.identity_upcall"
orig="$(do_facet mds1 "$LCTL get_param -n $param")"
stack_trap "do_facet mds1 $LCTL set_param $param=$orig" EXIT
# identity_upcall accepts an absolute path to an executable,
# or NONE (case insensitive)
do_facet mds1 $LCTL set_param $param=/path/to/prog ||
error "set_param $param=/path/to/prog failed (1)"
do_facet mds1 $LCTL set_param $param=prog &&
error "set_param $param=prog should fail (1)"
do_facet mds1 $LCTL set_param $param=NONE ||
error "set_param $param=NONE failed (1)"
do_facet mds1 $LCTL set_param $param=none ||
error "set_param $param=none failed (1)"
if $GSS; then
param="sptlrpc.gss.rsi_upcall"
orig="$(do_facet mds1 "$LCTL get_param -n $param")"
stack_trap "do_facet mds1 $LCTL set_param $param=$orig" EXIT
# rsi_upcall only accepts an absolute path to an executable
do_facet mds1 $LCTL set_param $param=prog &&
error "set_param $param=prog should fail (2)"
do_facet mds1 $LCTL set_param $param=NONE &&
error "set_param $param=NONE should fail (2)"
do_facet mds1 $LCTL set_param $param=/path/to/prog ||
error "set_param $param=/path/to/prog failed (2)"
fi
}
run_test 69 "check upcall incorrect values"
test_70() {
local param_mgs=$(mktemp $TMP/$tfile-mgs.XXXXXX)
local param_copy=$(mktemp $TMP/$tfile-copy.XXXXXX)
stack_trap "rm -f $param_mgs $param_copy" EXIT
(( $MDS1_VERSION > $(version_code 2.15.61) )) ||
skip "Need MDS version at least 2.15.61"
if ! $SHARED_KEY; then
skip "need shared key feature for this test"
fi
[[ "$ost1_FSTYPE" == ldiskfs ]] ||
skip "ldiskfs only test (using debugfs)"
# unmount then remount the Lustre filesystem, to make sure llogs
# are copied locally
export SK_NO_KEY=false
stopall || error "stopall failed"
init_gss
mountmgs || error "mountmgs failed"
mountmds || error "mountmds failed"
mountoss || error "mountoss failed"
mountcli || error "mountcli failed"
lfs df -h
unset SK_NO_KEY
do_facet mgs "sync ; sync"
do_facet mgs "$DEBUGFS -c -R 'ls CONFIGS/' $(mgsdevname)"
do_facet mgs "$DEBUGFS -c -R 'dump CONFIGS/$FSNAME-sptlrpc $param_mgs' \
$(mgsdevname)"
do_facet mgs "llog_reader $param_mgs" | grep -vE "SKIP|marker" |
grep "^#" > $param_mgs
cat $param_mgs
if ! combined_mgs_mds; then
do_facet mds1 "sync ; sync"
do_facet mds1 "$DEBUGFS -c -R 'ls CONFIGS/' $(mdsdevname 1)"
do_facet mds1 "$DEBUGFS -c -R 'dump CONFIGS/$FSNAME-sptlrpc \
$param_copy' $(mdsdevname 1)"
do_facet mds1 "llog_reader $param_copy" |
grep -vE "SKIP|marker" | grep "^#" > $param_copy
cat $param_copy
cmp -bl $param_mgs $param_copy ||
error "sptlrpc llog differ in mds"
rm -f $param_copy
fi
do_facet ost1 "sync ; sync"
do_facet ost1 "$DEBUGFS -c -R 'ls CONFIGS/' $(ostdevname 1)"
do_facet ost1 "$DEBUGFS -c -R 'dump CONFIGS/$FSNAME-sptlrpc \
$param_copy' $(ostdevname 1)"
do_facet ost1 "llog_reader $param_copy" | grep -vE "SKIP|marker" |
grep "^#" > $param_copy
cat -A $param_copy
cmp -bl $param_mgs $param_copy ||
error "sptlrpc llog differ at ost1"
rm -f $param_copy
do_facet ost2 "sync ; sync"
do_facet ost2 "$DEBUGFS -c -R 'ls CONFIGS/' $(ostdevname 2)"
do_facet ost2 "$DEBUGFS -c -R 'dump CONFIGS/$FSNAME-sptlrpc \
$param_copy' $(ostdevname 2)"
do_facet ost2 "llog_reader $param_copy" | grep -vE "SKIP|marker" |
grep "^#" > $param_copy
cat -A $param_copy
cmp -bl $param_mgs $param_copy ||
error "sptlrpc llog differ at ost2"
}
run_test 70 "targets have local copy of sptlrpc llog"
test_71() {
local vaultdir=$DIR/$tdir/vault
local projid=101
local res
(( $MDS1_VERSION >= $(version_code 2.15.63) )) ||
skip "Need MDS version at least 2.15.63"
[[ $($LCTL get_param mdc.*.import) =~ client_encryption ]] ||
skip "need encryption support"
which fscrypt || skip_env "Need fscrypt"
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
yes | fscrypt setup --force --verbose ||
echo "fscrypt global setup already done"
sed -i 's/\(.*\)policy_version\(.*\):\(.*\)\"[0-9]*\"\(.*\)/\1policy_version\2:\3"2"\4/' \
/etc/fscrypt.conf
yes | fscrypt setup --verbose $MOUNT ||
echo "fscrypt setup $MOUNT already done"
stack_trap "rm -rf $MOUNT/.fscrypt"
mkdir -p $vaultdir
stack_trap "rm -rf $vaultdir"
$LFS project -p $projid -s $vaultdir
$LFS project -d $vaultdir
res=$($LFS project -d $vaultdir | awk '{print $1}')
[[ "$res" == "$projid" ]] ||
error "project id set to $res instead of $projid"
res=$($LFS project -d $vaultdir | awk '{print $2}')
[[ "$res" == "P" ]] ||
error "project id should have inherit flag (1)"
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_71 $vaultdir ||
error "fscrypt encrypt $vaultdir failed"
$LFS project -d $vaultdir
res=$($LFS project -d $vaultdir | awk '{print $1}')
[[ "$res" == "$projid" ]] ||
error "project id changed to $res after enc"
res=$($LFS project -d $vaultdir | awk '{print $2}')
[[ "$res" == "P" ]] ||
error "project id should have inherit flag (2)"
touch $vaultdir/fileA || error "touch $vaultdir/fileA failed"
$LFS project $vaultdir/fileA
res=$($LFS project $vaultdir/fileA | awk '{print $1}')
[[ "$res" == "$projid" ]] ||
error "project id on fileA is $res after enc"
mkdir $vaultdir/dirA || error "touch $vaultdir/dirA failed"
$LFS project -d $vaultdir/dirA
res=$($LFS project -d $vaultdir/dirA | awk '{print $1}')
[[ "$res" == "$projid" ]] ||
error "project id on dirA is $res after enc"
res=$($LFS project -d $vaultdir/dirA | awk '{print $2}')
[[ "$res" == "P" ]] ||
error "project id should have inherit flag (3)"
}
run_test 71 "encryption does not remove project flag"
dyn_nm_helper() {
local facet=$1
local mgsnm=mgsnm
local mgsnids=1.1.0.[1-100]@tcp
local mgsnids2=1.0.0.[1-100]@tcp
local mgsclid=600
local mgsfsid=2000
local nm=nm_test72
local nids=1.1.1.[1-100]@tcp
local startnid=1.1.1.1@tcp
local endnid=1.1.1.100@tcp
local subnids1=1.1.1.[2-50]@tcp
local subnids2=1.1.1.[51-100]@tcp
local subnids3=1.1.1.[2-25]@tcp
local subnids4=1.1.1.[51-52]@tcp
local subnids5=1.1.1.[26-60]@tcp
local subnids6=1.1.1.[1-60]@tcp
local clid=500
local fsid=1000
local properties="audit_mode deny_unknown forbid_encryption \
readonly_mount"
local sepol="1:mls:31:40afb76d077c441b69af58cccaaa2ca63641ed6e21b0a887dc21a684f508b78f"
local rbac_val
local raise
local val
activedefault=$(do_facet mgs $LCTL get_param -n nodemap.active)
if [[ "$activedefault" != "1" ]]; then
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
stack_trap cleanup_active EXIT
fi
do_facet mgs $LCTL nodemap_set_fileset --name default \
--fileset "/deffset" ||
error "setting fileset on default failed"
raise=$(do_facet mgs $LCTL get_param -n \
nodemap.default.child_raise_privileges)
if [[ -n "$raise" ]]; then
do_facet mgs $LCTL nodemap_modify --name default \
--property child_raise_privileges --value all ||
error "modify raise_privileges for default on MGS failed"
wait_nm_sync default child_raise_privileges
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property child_raise_privileges --value $raise" EXIT
fi
do_facet mgs $LCTL nodemap_add $mgsnm ||
error "adding $mgsnm on MGS failed"
stack_trap "do_facet mgs $LCTL nodemap_del $mgsnm" EXIT
do_facet mgs $LCTL nodemap_add_range --name $mgsnm --range $mgsnids ||
error "add_range for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_add_idmap --name $mgsnm --idtype uid \
--idmap $mgsclid:$mgsfsid ||
error "add_idmap for $mgsnm on MGS failed"
wait_nm_sync $mgsnm idmap
rbac_val=$(do_facet mgs $LCTL get_param -n nodemap.$mgsnm.rbac)
stack_trap "do_facet $facet $LCTL nodemap_del $nm || true" EXIT
# check that persistent nodemap cannot be created on non MGS nodes
if [[ "$(facet_active_host mgs)" != \
"$(facet_active_host $facet)" ]]; then
do_facet $facet $LCTL nodemap_add $nm &&
error "static nodemap on server should fail"
fi
do_facet $facet $LCTL nodemap_add -d $nm &&
error "dynamic nodemap without parent should fail"
do_facet $facet $LCTL nodemap_add -d -p default $nm ||
error "dynamic nodemap on server failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val"
fi
do_facet $facet $LCTL nodemap_add_range --name $nm --range $nids ||
error "dynamic add_range on server failed"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.ranges |
awk 'BEGIN{RS=", "} $1=="start_nid:"{print $2 ; exit}')
[[ "$val" == "$startnid" ]] ||
error "dynamic nodemap wrong start nid range $val"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.ranges |
awk 'BEGIN{RS=", "} $1=="end_nid:"{print $2 ; exit}')
[[ "$val" == "$endnid" ]] ||
error "dynamic nodemap wrong end nid range $val"
do_facet $facet $LCTL nodemap_add_idmap --name $nm --idtype uid \
--idmap $clid:$fsid ||
error "dynamic add_idmap on server failed"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.idmap |
awk 'BEGIN{RS=", "} $1=="client_id:"{print $2 ; exit}')
(( val == clid )) || error "dynamic nodemap wrong client id $val"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.idmap |
awk 'BEGIN{RS=", "} $1=="fs_id:"{print $2 ; exit}')
(( val == fsid )) || error "dynamic nodemap wrong fs id $val"
for prop in $properties; do
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 1 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
(( val == 1 )) || error "incorrect $prop $val"
done
prop=admin
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 1 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.admin_nodemap)
(( val == 1 )) || error "incorrect $prop $val"
prop=trusted
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 0 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.trusted_nodemap)
(( val == 0 )) || error "incorrect $prop $val"
prop=map_mode
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value uid ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
[[ "$val" == "uid" ]] || error "incorrect $prop $val"
prop=rbac
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value file_perms ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
[[ "$val" == "file_perms" ]] || error "incorrect $prop $val"
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value all ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
[[ "$val" == "$rbac_val" ]] || error "incorrect $prop $val"
prop=squash_uid
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 77 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
(( val == 77 )) || error "incorrect $prop $val"
prop=squash_gid
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 77 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
(( val == 77 )) || error "incorrect $prop $val"
prop=squash_projid
do_facet $facet $LCTL nodemap_modify --name $nm \
--property $prop --value 77 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
(( val == 77 )) || error "incorrect $prop $val"
prop=sepol
do_facet $facet $LCTL nodemap_set_sepol --name $nm \
--sepol $sepol ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop)
[[ "$val" == "$sepol" ]] || error "incorrect $prop $val"
prop=offset
do_facet $facet $LCTL nodemap_add_offset --name $nm \
--offset 100000 --limit 200000 ||
error "dynamic modify of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop |
awk '$1 == "start_uid:" {print $2}' | sed s+,++)
(( val == 100000 )) || error "incorrect $prop start_uid $val"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop |
awk '$1 == "limit_uid:" {print $2}' | sed s+,++)
(( val == 200000 )) || error "incorrect $prop limit_uid $val"
do_facet $facet $LCTL nodemap_del_offset --name $nm ||
error "dynamic del of $prop failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop |
awk '$1 == "start_uid:" {print $2}' | sed s+,++)
(( val == 0 )) || error "incorrect $prop start_uid $val"
val=$(do_facet $facet $LCTL get_param -n nodemap.$nm.$prop |
awk '$1 == "limit_uid:" {print $2}' | sed s+,++)
(( val == 0 )) || error "incorrect $prop limit_uid $val"
val=$(do_facet $facet $LCTL nodemap_test_id --nid $startnid \
--idtype uid --id $clid)
(( val == fsid )) || error "dynamic test_id on server failed"
do_facet $facet $LCTL nodemap_del_idmap --name $nm --idtype uid \
--idmap $clid:$fsid ||
error "dynamic del_idmap on server failed"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.idmap |
awk 'BEGIN{RS=", "} $1=="client_id:"{print $2 ; exit}')
[[ -z "$val" ]] || error "idmap should be empty, got $val"
val=$(do_facet $facet $LCTL nodemap_test_nid $startnid)
[[ "$val" == "$nm" ]] || error "dynamic test_nid on server failed"
do_facet $facet $LCTL nodemap_add -d -p $nm ${nm}_1 ||
error "nodemap add ${nm}_1 on server failed"
stack_trap "do_facet $facet $LCTL nodemap_del ${nm}_1 || true" EXIT
do_facet $facet $LCTL nodemap_add_range --name ${nm}_1 \
--range $subnids1 ||
error "add_range for ${nm}_1 failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.${nm}_1.parent)
[[ "$val" == "$nm" ]] ||
error "parent of ${nm}_1 should be $nm, got $val"
do_facet $facet $LCTL nodemap_add -d -p $nm ${nm}_2 ||
error "nodemap add ${nm}_2 on server failed"
stack_trap "do_facet $facet $LCTL nodemap_del ${nm}_2 || true" EXIT
do_facet $facet $LCTL nodemap_add_range --name ${nm}_2 \
--range $subnids2 ||
error "add_range for ${nm}_2 failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.${nm}_2.parent)
[[ "$val" == "$nm" ]] ||
error "parent of ${nm}_2 should be $nm, got $val"
do_facet $facet $LCTL nodemap_add -d -p ${nm}_1 ${nm}_3 ||
error "nodemap add ${nm}_3 on server failed"
stack_trap "do_facet $facet $LCTL nodemap_del ${nm}_3 || true" EXIT
do_facet $facet $LCTL nodemap_add_range --name ${nm}_3 \
--range $subnids4 &&
error "nodemap ${nm}_3 should not accept range $subnids4"
do_facet $facet $LCTL nodemap_add_range --name ${nm}_3 \
--range $subnids5 &&
error "nodemap ${nm}_3 should not accept range $subnids5"
do_facet $facet $LCTL nodemap_add_range --name ${nm}_3 \
--range $subnids6 &&
error "nodemap ${nm}_3 should not accept range $subnids6"
do_facet $facet $LCTL nodemap_add_range --name ${nm}_3 \
--range $subnids3 ||
error "add_range $subnids3 for ${nm}_3 failed"
val=$(do_facet $facet $LCTL get_param -n nodemap.${nm}_3.parent)
[[ "$val" == "${nm}_1" ]] ||
error "parent of ${nm}_3 should be ${nm}_1, got $val"
val=$(do_facet $facet $LCTL get_param -n nodemap.${nm}_3.squash_projid)
(( val == 77 )) || error "squash_projid should be inherited, got $val"
do_facet $facet $LCTL nodemap_del_range --name $nm --range $nids ||
error "dynamic del_range on server failed"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.ranges |
awk 'BEGIN{RS=", "} $1=="start_nid:"{print $2 ; exit}')
[[ -z "$val" ]] || error "nid range should be empty, got $val"
do_facet $facet $LCTL nodemap_del $nm ||
error "dynamic nodemap del on server failed"
val=$(do_facet $facet $LCTL get_param nodemap.$nm.id)
[[ -z "$val" ]] || error "nodemap should be gone, got $val"
# changes to persistent nodemaps should not be possible on non-MGS nodes
if [[ "$(facet_active_host mgs)" != \
"$(facet_active_host $facet)" ]]; then
do_facet $facet $LCTL nodemap_add_range --name $mgsnm \
--range $mgsnids2 &&
error "add_range $mgsnm on server should fail"
do_facet $facet $LCTL nodemap_del_range --name $mgsnm \
--range $mgsnids &&
error "del_range $mgsnm on server should fail"
do_facet $facet $LCTL nodemap_add_idmap --name $mgsnm \
--idtype gid --idmap $mgsclid:$mgsfsid &&
error "add_idmap $mgsnm on server should fail"
do_facet $facet $LCTL nodemap_del_idmap --name $mgsnm \
--idtype uid --idmap $mgsclid:$mgsfsid &&
error "del_idmap $mgsnm on server should fail"
do_facet $facet $LCTL nodemap_modify --name $mgsnm \
--property squash_projid --value 77 &&
error "modify $mgsnm on server should fail"
do_facet $facet $LCTL nodemap_del $mgsnm &&
error "nodemap del $mgsnm on server should fail"
fi
do_facet $facet $LCTL get_param -R 'nodemap.*'
}
test_72a() {
(( OST1_VERSION >= $(version_code 2.16.54) )) ||
skip "Need OSS >= 2.16.54 dynamic nodemaps"
dyn_nm_helper ost1
}
run_test 72a "dynamic nodemap properties on OSS"
test_72b() {
(( MDS1_VERSION >= $(version_code 2.16.54) )) ||
skip "Need MDS >= 2.16.54 dynamic nodemaps"
dyn_nm_helper mds1
}
run_test 72b "dynamic nodemap properties on MDS"
test_72c() {
local mgsnm=mgsnm
local nm=nm_test72c
local val
(( MDS1_VERSION >= $(version_code 2.16.54) )) ||
skip "Need MDS >= 2.16.54 dynamic nodemaps"
do_facet mgs $LCTL nodemap_add $mgsnm ||
error "adding $mgsnm on MGS failed"
stack_trap "do_facet mgs $LCTL nodemap_del $mgsnm" EXIT
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property child_raise_privileges --value trusted ||
error "modify raise_privileges for $mgsnm on MGS failed (1)"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property admin --value 0 ||
error "modify admin for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property trusted --value 0 ||
error "modify trusted for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property deny_unknown --value 0 ||
error "modify deny_unknown for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property readonly_mount --value 0 ||
error "modify readonly_mount for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property deny_mount --value 1 ||
error "modify deny_mount for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property rbac --value file_perms,quota_ops,byfid_ops ||
error "modify rbac for $mgsnm on MGS failed"
wait_nm_sync $mgsnm rbac '' inactive
do_facet mds1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (1)"
stack_trap "do_facet mds1 $LCTL nodemap_del $nm || true" EXIT
val=$(do_facet mds1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (1)"
fi
val=$(do_facet mds1 $LCTL get_param -n \
nodemap.$nm.child_raise_privileges)
[[ $val == "trusted" ]] ||
error "dyn nodemap should inherit child_raise_privileges"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property admin --value 1 &&
error "modify admin for $nm on mds1 should fail"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property trusted --value 1 ||
error "modify trusted for $nm on mds1 failed"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property deny_unknown --value 1 ||
error "modify deny_unknown for $nm on mds1 failed"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property readonly_mount --value 1 ||
error "modify readonly_mount for $nm on mds1 failed"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property rbac --value file_perms,quota_ops,byfid_ops,dne_ops &&
error "modify rbac for $nm on mds1 should fail (1)"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property rbac --value file_perms ||
error "modify rbac for $nm on mds1 failed (1)"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property child_raise_privileges \
--value trusted,admin &&
error "modify nm.child_raise_privileges for $nm on mds1 should fail"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property deny_mount --value 0 &&
error "modify deny_mount for $nm on mds1 should fail"
do_facet mds1 $LCTL nodemap_del $nm ||
error "failed to delete dynamic nodemap $nm"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property child_raise_privileges --value trusted,dne_ops ||
error "modify raise_privileges for $mgsnm on MGS failed (2)"
wait_nm_sync $mgsnm child_raise_privileges '' inactive
do_facet mds1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (2)"
val=$(do_facet mds1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (2)"
fi
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property rbac --value file_perms,quota_ops,byfid_ops,dne_ops ||
error "modify rbac for $nm on mds1 failed (2)"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property rbac --value file_perms,quota_ops,byfid_ops,chlg_ops &&
error "modify rbac for $nm on mds1 should fail (2)"
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property child_raise_privileges \
--value trusted ||
error "modify nm.child_raise_privileges for $nm on mds1 failed (1)"
do_facet mds1 $LCTL nodemap_del $nm ||
error "failed to delete dynamic nodemap $nm"
do_facet mgs $LCTL nodemap_modify --name $mgsnm \
--property child_raise_privileges \
--value child_raise_privs,trusted,dne_ops ||
error "modify raise_privileges for $mgsnm on MGS failed (3)"
wait_nm_sync $mgsnm child_raise_privileges '' inactive
do_facet mds1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (3)"
val=$(do_facet mds1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (3)"
fi
do_facet mds1 $LCTL nodemap_modify --name $nm \
--property child_raise_privileges \
--value child_raise_privs,trusted,dne_ops,admin ||
error "modify nm.child_raise_privileges for $nm on mds1 failed (2)"
do_facet mds1 $LCTL get_param -R nodemap.*
}
run_test 72c "child_raise_privileges nodemap property"
cleanup_72d() {
local nm_name=${1:-"c0"}
local dynnm1=${2:-"dyn1"}
local dynnm2=${3:-"dyn2"}
do_facet ost1 $LCTL nodemap_del $dynnm1 || true
do_facet ost1 $LCTL nodemap_del $dynnm2 || true
do_facet mgs $LCTL nodemap_del $nm_name
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0
wait_nm_sync default trusted_nodemap
}
test_72d() {
local mgsnm=mgsnm
local nm=nm_test72d
local nm2=subnm_test72d
local val
local delete_dyn_nm=false
is_multi_fileset_supported "ost1" ||
skip "Need OSS >= 2.16.57 for multiple filesets"
# When MGS and OST are colocated, we need to explicitly remove the
# dynamic nodemap on earlier versions (LU-19478) because nodemap
# synchronization does not explicitly wipe them.
[[ "$(facet_active_host mgs)" == "$(facet_active_host ost1)" ]] &&
(( OST1_VERSION < $(version_code 2.16.61) )) &&
delete_dyn_nm=true
stack_trap "cleanup_72d $mgsnm $nm $nm2" EXIT
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
do_facet mgs $LCTL nodemap_add $mgsnm ||
error "adding $mgsnm on MGS failed"
wait_nm_sync $mgsnm id '' inactive
do_facet ost1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (1)"
val=$(do_facet ost1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (1)"
fi
val=$(do_facet_check_fileset ost1 $nm "" "primary")
[[ "$val" == "" ]] ||
error "$nm should have empty fileset (1)"
local filesetp="/subdir"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $filesetp ||
error "dynamic modify fileset to $filesetp failed"
val=$(do_facet_check_fileset ost1 $nm "$filesetp" "primary")
[[ "$val" == "$filesetp" ]] ||
error "$nm should have fileset $filesetp (1)"
do_facet ost1 $LCTL nodemap_fileset_del --name $nm \
--fileset $filesetp ||
error "dynamic del fileset $filesetp failed"
val=$(do_facet_check_fileset ost1 $nm "" "primary")
[[ "$val" == "" ]] ||
error "$nm should have empty fileset (2)"
do_facet mgs $LCTL nodemap_set_fileset --name $mgsnm \
--fileset $filesetp ||
error "modify fileset for $mgsnm on MGS failed"
wait_nm_sync $mgsnm fileset '' inactive
if $delete_dyn_nm; then
do_facet ost1 $LCTL nodemap_del $nm
fi
do_facet ost1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (2)"
val=$(do_facet ost1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (1)"
fi
val=$(do_facet_check_fileset ost1 $nm "$filesetp" "primary")
[[ "$val" == "$filesetp" ]] ||
error "$nm should have fileset $filesetp (2)"
local fileset1="/sub"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset1 &&
error "dynamic modify fileset to $fileset1 should fail"
val=$(do_facet_check_fileset ost1 $nm "$filesetp" "primary")
[[ "$val" == "$filesetp" ]] ||
error "$nm should have fileset $filesetp (3)"
local fileset2="/subdirother"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset2 &&
error "dynamic modify fileset to $fileset2 should fail"
val=$(do_facet_check_fileset ost1 $nm "$filesetp" "primary")
[[ "$val" == "$filesetp" ]] ||
error "$nm should have fileset $filesetp (4)"
local fileset3="/subdir/mydir"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset3 ||
error "dynamic modify fileset to $fileset3 failed (1)"
val=$(do_facet_check_fileset ost1 $nm "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm should have fileset $fileset3 (1)"
do_facet ost1 $LCTL nodemap_fileset_del --name $nm \
--fileset $fileset3 &&
error "dynamic del fileset $fileset3 should fail"
val=$(do_facet_check_fileset ost1 $nm "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm should have fileset $fileset3 (2)"
do_facet ost1 $LCTL nodemap_add -d -p $nm $nm2 ||
error "dynamic nodemap on server failed (3)"
val=$(do_facet ost1 $LCTL get_param -n nodemap.$nm2.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (2)"
fi
val=$(do_facet_check_fileset ost1 $nm2 "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm2 should have fileset $fileset3 (1)"
local fileset4="/subdir/myd"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm2 \
--fileset $fileset4 &&
error "dynamic modify fileset to $fileset4 should fail"
val=$(do_facet_check_fileset ost1 $nm2 "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm2 should have fileset $fileset3 (2)"
local fileset5="/subdir/mydirother"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm2 \
--fileset $fileset5 &&
error "dynamic modify fileset to $fileset5 should fail"
val=$(do_facet_check_fileset ost1 $nm2 "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm2 should have fileset $fileset3 (3)"
local fileset6="/subdir/mydir/dir2"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm2 \
--fileset $fileset6 ||
error "dynamic modify fileset to $fileset6 failed"
val=$(do_facet_check_fileset ost1 $nm2 "$fileset6" "primary")
[[ "$val" == "$fileset6" ]] ||
error "$nm2 should have fileset $fileset6 (4)"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm2 \
--fileset $fileset3 ||
error "dynamic modify fileset to $fileset3 failed (2)"
val=$(do_facet_check_fileset ost1 $nm2 "$fileset3" "primary")
[[ "$val" == "$fileset3" ]] ||
error "$nm2 should have fileset $fileset3 (5)"
do_facet ost1 $LCTL get_param -R nodemap.*
# tests for LU-19426 below. Fix not included in 2.16.57
(( $MDS1_VERSION >= $(version_code 2.16.58) )) ||
return 0
do_facet ost1 $LCTL nodemap_del $nm ||
error "removing dynamic nodemap on server failed"
do_facet mgs $LCTL nodemap_fileset_del --name $mgsnm --all ||
error "deleting fileset for $mgsnm on MGS failed"
do_facet mgs $LCTL nodemap_fileset_add --name $mgsnm \
--fileset $filesetp --alt ||
error "adding alt fileset for $mgsnm on MGS failed"
wait_nm_sync_fileset $mgsnm "$filesetp" "$filesetp" "alternate"
do_facet ost1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed (4)"
val=$(do_facet ost1 $LCTL get_param -n nodemap.$nm.id)
if [[ -z "$val" || "$val" == "0" ]]; then
error "dynamic nodemap wrong id $val (3)"
fi
val=$(do_facet_check_fileset ost1 $nm "$filesetp" "alternate")
[[ "$val" == "$filesetp" ]] ||
error "$nm should have fileset $filesetp (6)"
local fileset7="/outsidedir"
# attempt to set fileset outside parent's namespace restrictions.
# previously succeeded and fixed by LU-19426
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset7 &&
error "dyn set fileset to $fileset7 should fail (out-of-bounds)"
do_facet ost1 $LCTL nodemap_fileset_add --name $nm \
--fileset $fileset7 &&
error "dyn add fileset to $fileset7 should fail (out-of-bounds)"
local fileset8="/subdir/mydir"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm \
--fileset $fileset8 ||
error "dyn set prim fileset to $fileset8 failed"
do_facet ost1 $LCTL nodemap_set_fileset --name $nm --fileset 'clear' ||
error "remove prim fileset failed"
do_facet ost1 $LCTL nodemap_fileset_add --name $nm \
--fileset $fileset8 ||
error "dyn add prim fileset to $fileset8 failed"
}
run_test 72d "fileset inheritance for dynamic nodemap"
cleanup_72e() {
# unmount client
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# reset and deactivate nodemaps, remount client
cleanup_local_client_nodemap
# remount client on $MOUNT_2
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} || error "remount failed"
fi
wait_ssk
}
test_72e() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local nm=c0
local dynnm=c1
local exp_cnt_orig
local exp_cnt_new
(( $MDS1_VERSION >= $(version_code 2.16.58) )) ||
skip "Need MDS with reclassify members support"
if $SHARED_KEY; then
skip "need non-shared key for this test"
fi
stack_trap cleanup_72e EXIT
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# setup nodemap
setup_local_client_nodemap $nm 1 1
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed"
wait_ssk
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_orig=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep -c $client_nid")
(( exp_cnt_orig != 0 )) ||
error "no exports for $client_nid found on $nm"
# create dynamic nodemap
do_facet mds1 $LCTL nodemap_add -d -p $nm $dynnm ||
error "failed to create dynamic nodemap"
do_facet mds1 $LCTL nodemap_add_range --name $dynnm \
--range $client_nid ||
error "add_range on $dynnm failed"
# check nodemap exports, without remounting
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep -c $client_nid")
(( exp_cnt_new == 0 )) ||
error "found $exp_cnt_new exports for $client_nid on $nm"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$dynnm.exports |
grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $dynnm, expected $exp_cnt_orig"
# remove dynamic nodemap
do_facet mds1 $LCTL nodemap_del $dynnm ||
error "failed to delete dynamic nodemap"
# check nodemap exports again
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $nm, expected $exp_cnt_orig"
}
run_test 72e "dynamic nodemap reclassify"
cleanup_72f() {
local nm=$1
local dyn_nm=$2
do_facet ost1 $LCTL nodemap_del $dyn_nm
nodemap_clear_filesets_and_wait $nm
do_facet mgs $LCTL nodemap_del $nm
wait_nm_sync $nm id ''
}
test_72f() {
local mgsnm="mgsnm_test72f"
local nm="dynnm_test72f"
local fileset_prim="/primary"
local fileset_alt1="/alt1"
local fileset_alt2="/alt2"
local delete_dyn_nm=false
local val
is_multi_fileset_supported "ost1" ||
skip "Need OSS >= 2.16.57 for multiple filesets"
# When MGS and OST are colocated, we need to explicitly remove the
# dynamic nodemap on earlier versions (LU-19478) because nodemap
# synchronization does not explicitly wipe them.
[[ "$(facet_active_host mgs)" == "$(facet_active_host ost1)" ]] &&
(( OST1_VERSION < $(version_code 2.16.61) )) &&
delete_dyn_nm=true
stack_trap "cleanup_72f $mgsnm $nm" EXIT
# create parent nodemap
do_facet mgs $LCTL nodemap_add $mgsnm ||
error "adding $mgsnm on MGS failed"
wait_nm_sync $mgsnm id '' inactive
# create dynamic nodemap
do_facet ost1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed"
val=$(do_facet_check_fileset ost1 $nm "" "primary")
[[ "$val" == "" ]] ||
error "$nm should have empty fileset"
do_facet ost1 $LCTL nodemap_info --name $nm
# initial tests without parent filesets, i.e., no restrictions
do_facet ost1 $LCTL nodemap_fileset_add --name $nm \
--fileset $fileset_prim ||
error "add fileset $fileset_prim to $nm failed"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "primary")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should have fileset $fileset_prim"
do_facet ost1 $LCTL nodemap_fileset_add --name $nm \
--fileset $fileset_alt1 --alt ||
error "add fileset $fileset_alt1 to $nm failed"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt1" "alternate")
[[ "$val" == "$fileset_alt1" ]] ||
error "$nm should have fileset $fileset_alt1"
do_facet ost1 $LCTL nodemap_fileset_add --name $nm \
--fileset $fileset_alt2 --alt --ro ||
error "add fileset $fileset_alt2 to $nm failed"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt2" "alternate" "ro")
[[ "$val" == "$fileset_alt2" ]] ||
error "$nm should have fileset $fileset_alt2"
do_facet ost1 $LCTL nodemap_info --name $nm --property fileset
# shuffle filesets around with fileset modify
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_prim --alt ||
error "failed to convert primary fileset to alt fileset"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "alternate")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should have fileset $fileset_prim"
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_alt2 --prim --rw ||
error "failed to convert alt fileset to primary"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt2" "primary")
[[ "$val" == "$fileset_alt2" ]] ||
error "$nm should have fileset $fileset_alt2"
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_alt1 --ro ||
error "failed to change alt fileset to read-only"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt1" "alternate" "ro")
[[ "$val" == "$fileset_alt1" ]] ||
error "$nm should have fileset $fileset_alt1"
do_facet ost1 $LCTL nodemap_info --name $nm --property fileset
# add filesets to parent nodemap (deletes dynamic nodemap)
do_facet mgs $LCTL nodemap_fileset_add --name $mgsnm \
--fileset $fileset_prim --ro ||
error "add fileset $fileset_prim to $mgsnm failed"
do_facet mgs $LCTL nodemap_fileset_add --name $mgsnm \
--fileset $fileset_alt1 --alt ||
error "add fileset $fileset_alt1 to $mgsnm failed"
do_facet mgs $LCTL nodemap_fileset_add --name $mgsnm \
--fileset $fileset_alt2 --alt --ro ||
error "add fileset $fileset_alt2 to $mgsnm failed"
wait_nm_sync $mgsnm fileset '' inactive
if $delete_dyn_nm; then
do_facet ost1 $LCTL nodemap_del $nm
fi
# create dynamic nodemap
do_facet ost1 $LCTL nodemap_add -d -p $mgsnm $nm ||
error "dynamic nodemap on server failed"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "primary" "ro")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should filesets set"
do_facet ost1 $LCTL nodemap_info --name $nm --property fileset
# 1. convert $fileset_prim to alternate (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_prim --alt ||
error "failed to convert primary fileset to alt fileset"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "alternate" "ro")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should have fileset $fileset_prim"
# 2. convert $fileset_alt2 to primary and change ro -> rw (should fail)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_alt2 --prim --rw &&
error "should not be able to convert ro alt fileset to rw prim"
# 3. convert $fileset_alt2 to prim and rename (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_alt2 --prim --rename "${fileset_alt2}/alt" ||
error "failed to convert alt fileset to primary"
val=$(do_facet_check_fileset ost1 $nm "${fileset_alt2}/alt" \
"primary" "ro")
[[ "$val" == "${fileset_alt2}/alt" ]] ||
error "$nm should have fileset ${fileset_alt2}/alt"
# 4. change $fileset_prim ro -> rw (should fail)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_prim --rw &&
error "should not be able to change ro alt fileset to rw"
# 5. change $fileset_alt1 rw -> ro (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_alt1 --ro ||
error "failed to change alt rw fileset to ro"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt1" "alternate" "ro")
[[ "$val" == "$fileset_alt1" ]] ||
error "$nm should have fileset $fileset_alt1"
# 6. rename $fileset_prim to /prim (should fail)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_prim --rename "/prim" &&
error "should not be able to rename primary fileset outside parent's namespace restrictions"
# 7. delete $fileset_alt2 (should succeed)
do_facet ost1 $LCTL nodemap_fileset_del --name $nm \
--fileset "${fileset_alt2}/alt" ||
error "failed to delete alt fileset ${fileset_alt2}/alt"
val=$(do_facet_check_fileset ost1 $nm "${fileset_alt2}/alt" "primary")
[[ -z "$val" ]] ||
error "$nm should not have fileset ${fileset_alt2}/alt"
# 8. delete $fileset_alt1 (should succeed)
do_facet ost1 $LCTL nodemap_fileset_del --name $nm \
--fileset $fileset_alt1 ||
error "failed to delete alt fileset $fileset_alt1"
val=$(do_facet_check_fileset ost1 $nm "$fileset_alt1" "alternate" "ro")
[[ -z "$val" ]] ||
error "$nm should not have fileset $fileset_alt1"
# 9. rename $fileset_primary and change ro -> rw (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset $fileset_prim --rename "${fileset_alt1}/alt" --rw ||
error "failed to rename primary fileset to ${fileset_alt1}/alt"
val=$(do_facet_check_fileset ost1 $nm "${fileset_alt1}/alt" "alternate")
# 10. rename $fileset_primary to /primary/prim (should fail)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset "${fileset_alt1}/alt" --rename "$fileset_prim" &&
error "should not be able to rename alt rw fileset to '/primary' which can only be read-only"
# 11. rename $fileset_primary and change rw -> ro (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset "${fileset_alt1}/alt" --rename "$fileset_prim" --ro ||
error "failed to rename alt fileset to $fileset_prim"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "alternate" "ro")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should have fileset $fileset_prim"
# 12. convert $fileset_primary to primary (should succeed)
do_facet ost1 $LCTL nodemap_fileset_modify --name $nm \
--fileset "$fileset_prim" --prim ||
error "failed to convert alt fileset to primary"
val=$(do_facet_check_fileset ost1 $nm "$fileset_prim" "primary" "ro")
[[ "$val" == "$fileset_prim" ]] ||
error "$nm should have fileset $fileset_prim"
# 13. attempt to clear remaining filesets (should fail)
do_facet ost1 $LCTL nodemap_fileset_del --name $nm --all &&
error "should not be able to clear filesets on dynamic nodemap"
do_facet ost1 $LCTL nodemap_info --name $nm --property fileset
}
run_test 72f "fileset_modify on dynamic nodemap"
test_73() {
local vaultdir1=$DIR/$tdir/vault1
local vaultdir2=$DIR/$tdir/vault2
local shortfname="short=a"
local longfname="longfilenamewitha=inthemiddletotestbehaviorregardingthedigestedform"
local fid
local digshort1
local digshort2
local diglong1
local diglong2
(( $MDS1_VERSION >= $(version_code 2.16.50) )) ||
skip "Need MDS version at least 2.16.50"
[[ $($LCTL get_param mdc.*.import) =~ client_encryption ]] ||
skip "need encryption support"
which fscrypt || skip_env "Need fscrypt"
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
yes | fscrypt setup --force --verbose ||
echo "fscrypt global setup already done"
sed -i 's/\(.*\)policy_version\(.*\):\(.*\)\"[0-9]*\"\(.*\)/\1policy_version\2:\3"2"\4/' \
/etc/fscrypt.conf
yes | fscrypt setup --verbose $MOUNT ||
echo "fscrypt setup $MOUNT already done"
stack_trap "rm -rf $MOUNT/.fscrypt"
# enable_filename_encryption tunable only available for client
# built against embedded llcrypt. If client is built against in-kernel
# fscrypt, file names are always encrypted.
$LCTL get_param mdc.*.connect_flags | grep -q name_encryption &&
nameenc=$(lctl get_param -n llite.*.enable_filename_encryption |
head -n1)
# begin with non-encrypted names
if [ -n "$nameenc" ] && (( nameenc != 0 )); then
$LCTL set_param llite.*.enable_filename_encryption=0
[ $? -eq 0 ] ||
error "set_param \
llite.*.enable_filename_encryption=1 failed"
fi
mkdir -p $vaultdir1
stack_trap "rm -rf $vaultdir1"
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_73a $vaultdir1 ||
error "fscrypt encrypt $vaultdir1 failed"
# activate changelogs
changelog_register || error "changelog_register failed"
local cl_user="${CL_USERS[$SINGLEMDS]%% *}"
changelog_users $SINGLEMDS | grep -q $cl_user ||
error "User $cl_user not found in changelog_users"
changelog_chmask ALL
touch $vaultdir1/$shortfname ||
error "touch $vaultdir1/$shortfname failed"
fid=$($LFS path2fid $vaultdir1/$shortfname)
fid="${fid:1:-1}"
fscrypt lock $vaultdir1 || error "fscrypt lock $vaultdir1 failed"
digshort1=$($LFS fid2path $MOUNT $fid)
digshort1=$(basename $digshort1)
echo mypass | fscrypt unlock $vaultdir1 ||
error "fscrypt unlock $vaultdir1 failed"
mrename $vaultdir1/$shortfname $vaultdir1/$longfname ||
error "mrename $vaultdir1/$shortfname failed"
fscrypt lock $vaultdir1 || error "fscrypt lock $vaultdir1 failed"
diglong1=$($LFS fid2path $MOUNT $fid)
diglong1=$(basename $diglong1)
# access changelogs
echo "changelogs dump"
changelog_dump || error "failed to dump changelogs"
digshort2=$(changelog_find -type CREAT -target-fid $fid |
awk '{print $12}')
[[ $digshort1 == $digshort2 ]] ||
error "name $digshort2 in CREAT is not $digshort1"
digshort2=$(changelog_find -type RENME -source-fid $fid |
awk '{print $15}')
[[ $digshort1 == $digshort2 ]] ||
error "name $digshort2 in RENME is not $digshort1"
diglong2=$(changelog_find -type RENME -source-fid $fid |
awk '{print $12}')
[[ $diglong1 == $diglong2 ]] ||
error "name $diglong2 in RENME is not $diglong1"
echo "changelogs clear"
changelog_clear 0 || error "failed to clear changelogs"
# now switch to encrypted names
if [ -n "$nameenc" ] && (( nameenc != 1 )); then
$LCTL set_param llite.*.enable_filename_encryption=1
[ $? -eq 0 ] ||
error "set_param \
llite.*.enable_filename_encryption=1 failed"
stack_trap \
"$LCTL set_param llite.*.enable_filename_encryption=0"
fi
$LFS mkdir -c1 -i $((MDSCOUNT-1)) $vaultdir2
stack_trap "rm -rf $vaultdir2"
echo -e 'mypass\nmypass' | fscrypt encrypt --verbose \
--source=custom_passphrase --name=protector_73b $vaultdir2 ||
error "fscrypt encrypt $vaultdir2 failed"
touch $vaultdir2/$shortfname ||
error "touch $vaultdir2/$shortfname failed"
fid=$($LFS path2fid $vaultdir2/$shortfname)
fid="${fid:1:-1}"
fscrypt lock $vaultdir2 || error "fscrypt lock $vaultdir2 failed"
digshort1=$($LFS fid2path $MOUNT $fid)
digshort1=$(basename $digshort1)
echo mypass | fscrypt unlock $vaultdir2 ||
error "fscrypt unlock $vaultdir2 failed"
mrename $vaultdir2/$shortfname $vaultdir2/$longfname ||
error "mrename $vaultdir2/$shortfname failed"
fscrypt lock $vaultdir2 || error "fscrypt lock $vaultdir2 failed"
diglong1=$($LFS fid2path $MOUNT $fid)
diglong1=$(basename $diglong1)
# generate a changelog record for rm_entry
is_rmentry_supported && {
echo "test rm_entry"
touch $DIR/$tdir/rmentry
$LFS rm_entry $DIR/$tdir/rmentry || error "lfs rm_entry"
}
# access changelogs
echo "changelogs dump"
changelog_dump || error "failed to dump changelogs"
digshort2=$(changelog_find -type CREAT -target-fid $fid |
awk '{print $12}')
[[ $digshort1 == $digshort2 ]] ||
error "name $digshort2 in CREAT is not $digshort1"
digshort2=$(changelog_find -type RENME -source-fid $fid |
awk '{print $15}')
[[ $digshort1 == $digshort2 ]] ||
error "name $digshort2 in RENME is not $digshort1"
diglong2=$(changelog_find -type RENME -source-fid $fid |
awk '{print $12}')
[[ $diglong1 == $diglong2 ]] ||
error "name $diglong2 in RENME is not $diglong1"
is_rmentry_supported && {
local cr
echo "verify rm_entry"
cr=$(changelog_find -type UNLNK -target-fid "0:0x0:0x0")
[[ -n $cr ]] || error "can't found rm_entry"
}
}
run_test 73 "encrypted names in changelogs"
test_74() {
local testfile="${DIR}/${tdir}/$tfile"
local deny_mount
# check that deny_mount flag exists
deny_mount=$(do_facet mgs \
$LCTL get_param -n nodemap.default.deny_mount)
[[ -n "$deny_mount" ]] ||
skip "Server does not have the deny_mount nodemap flag"
stack_trap cleanup_local_client_nodemap EXIT
umount_client $MOUNT || error "umount $MOUNT failed (1)"
# setup privileged nodemap for c0
setup_local_client_nodemap "c0" 1 1
# check default deny_mount flags
(( $deny_mount == 0 )) ||
error "wrong default for deny_mount flag on default nodemap"
deny_mount=$(do_facet mgs \
$LCTL get_param -n nodemap.c0.deny_mount)
(( $deny_mount == 0 )) ||
error "wrong default value for deny_mount on nodemap c0"
# mount client with active nodemap
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS} ||
error "re-mount failed (1)"
wait_ssk
# simple access test
$LFS mkdir -c 1 "${DIR}/$tdir" || error "mkdir ${DIR}/$tdir failed"
$LFS setstripe -c 1 $testfile || error "setstripe $testfile failed"
echo -n "a" > $testfile || error "(1) write $testfile failed"
# set deny_mount flag. Access should still work for existing clients
do_facet mgs $LCTL nodemap_modify --name c0 \
--property deny_mount --value 1
wait_nm_sync c0 deny_mount
echo -n "b" >> $testfile || error "(2) write $testfile failed"
cat $testfile > /dev/null || error "read $testfile failed"
# unmount client
umount_client $MOUNT || error "umount $MOUNT failed (2)"
# mount client should fail (nodemap is deny_mount)
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS} &&
error "mount should have failed. deny_mount flag is not honored"
# set active flag for c0. Access should work again
do_facet mgs $LCTL nodemap_modify --name c0 \
--property deny_mount --value 0
wait_nm_sync c0 deny_mount
zconf_mount_clients $HOSTNAME $MOUNT ${MOUNT_OPTS} ||
error "re-mount failed (2)"
wait_ssk
# check access
echo -n "c" >> $testfile || error "(3) write $testfile failed"
[[ $(cat $testfile) == "abc" ]] ||
error "read access test for $testfile failed"
}
run_test 74 "Set nodemap deny_mount flag"
check_ost_object_ids() {
local file=$1
local expected_uid=$2
local expected_gid=$3
local expected_projid=$4
local expected_mode=${5:-""}
local objdump=$DIR/$tdir/objdump
local obj_uid obj_gid obj_projid obj_mode
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
# Get the OST object path. We assume the file has one stripe on ost1
local fids=($($LFS getstripe $file | grep 0x))
local fid="${fids[3]}:${fids[2]}:0"
local objpath=$(ost_fid2_objpath ost1 $fid)
do_facet ost1 \
"$DEBUGFS -c -R 'stat $objpath' $(ostdevname 1)" > "$objdump"
read -r obj_uid obj_gid obj_projid obj_mode < <(
awk '
/^User:/ {u=$2; g=$4; p=$6}
/^Inode:/ {m=$6}
END {print u, g, p, m}
' "$objdump"
)
echo "OST object metadata dump for file '$file':"
cat $objdump
[[ "$obj_uid" == "$expected_uid" ]] ||
error "uid is not set to expected value $expected_uid"
[[ "$obj_gid" == "$expected_gid" ]] ||
error "gid is not set to expected value $expected_gid"
[[ "$obj_projid" == "$expected_projid" ]] ||
error "projid is not set to expected value $expected_projid"
if [[ -n "$expected_mode" ]]; then
[[ "$obj_mode" == "$expected_mode" ]] ||
error "mode is not set to expected value $expected_mode"
fi
}
check_mdt_inode_ids() {
local file=${1#${MOUNT}}
local expected_uid=$2
local expected_gid=$3
local expected_projid=$4
local objdump=$DIR/$tdir/objdump
if (( $MDSCOUNT != 1 )); then
echo "DNE not supported; checking IDs on MDT assumes a single MDT only"
return 0
fi
mkdir -p $DIR/$tdir || error "mkdir $DIR/$tdir failed"
do_facet mds1 "$DEBUGFS -c -R 'stat ROOT${file}' $(mdsdevname 1)" |
grep "Project" > $objdump
local obj_uid=$(awk '{print $2}' $objdump)
local obj_gid=$(awk '{print $4}' $objdump)
local obj_projid=$(awk '{print $6}' $objdump)
echo "MDT inode ids and size for file '$file': $(cat $objdump)"
[[ "$obj_uid" == "$expected_uid" ]] ||
error "uid is not set to expected value $expected_uid"
[[ "$obj_gid" == "$expected_gid" ]] ||
error "gid is not set to expected value $expected_gid"
[[ "$obj_projid" == "$expected_projid" ]] ||
error "projid is not set to expected value $expected_projid"
}
check_ids_sync() {
sync
# wait for asynchronous MDS-OST sync and force flush to OST
sync_all_data
wait_mds_ost_sync || error "wait_mds_ost_sync failed"
# drop_caches to flush inode cache so ID updates from chown or
# lfs project are visible through debugfs on the OST objects
do_facet ost1 "sync; sync; echo 3 > /proc/sys/vm/drop_caches"
# drop_caches to flush dentry cache so namespace updates from "mv"
# operations are visible through debugfs on the MDT
do_facet mds "sync; sync; echo 3 > /proc/sys/vm/drop_caches"
}
test_75() {
local testdir="${DIR}/${tdir}"
local projdir="${testdir}/projdir"
local tfile_write=${projdir}/${tfile}_write
local tfile_trunc=${projdir}/${tfile}_trunc
local tfile_creat=${projdir}/${tfile}_creat
local tfile_falloc=${projdir}/${tfile}_falloc
local tfile_write2=${testdir}/${tfile}_write2
local testdir_projid=42
local testfile_projid=43
local have_ost_punch_ids=false
local have_ost_punch_id_fix=false # LU-20420
# prior to 2.16.53 OST_PUNCH did not set OST IDs
(( $OST1_VERSION >= $(version_code 2.16.53) &&
$CLIENT_VERSION >= $(version_code 2.16.53) )) &&
have_ost_punch_ids=true
(( $CLIENT_VERSION >= $(version_code 2.17.54) )) &&
have_ost_punch_id_fix=true
[[ "$ost1_FSTYPE" == ldiskfs ]] ||
skip "ldiskfs only test (using debugfs)"
# setup
mkdir -p $projdir || error "mkdir $projdir failed"
stack_trap "rm -rf $DIR/$tdir" EXIT
$LFS project -s -p $testdir_projid $projdir ||
error "lfs project failed"
chown -R $USER0 $DIR/$tdir || error "chown Failed"
# setstripe is primarily used to force data being created on ost1
# OST_WRITE RPC (dd) - in projdir
$RUNAS_CMD -u $ID0 $LFS setstripe -c 1 -i 0 $tfile_write ||
error "setstripe for file $tfile_write failed"
$RUNAS_CMD -u $ID0 dd if=/dev/urandom of=$tfile_write bs=1M count=1 ||
error "dd for file $tfile_write failed"
# OST_WRITE RPC (dd) - not in projdir
$RUNAS_CMD -u $ID0 $LFS setstripe -c 1 -i 0 $tfile_write2 ||
error "setstripe for file $tfile_write2 failed"
$RUNAS_CMD -u $ID0 \
dd if=/dev/urandom of=$tfile_write2 bs=1M count=1 ||
error "dd for file $tfile_write2 failed"
if $have_ost_punch_ids; then
local truncate_user=$ID0
$RUNAS_CMD -u $ID0 $LFS setstripe -c 1 -i 0 $tfile_trunc ||
error "setstripe for file $tfile_trunc failed"
# OST_PUNCH RPC (truncate)
if $have_ost_punch_id_fix; then
truncate_user=$ID1
$RUNAS_CMD -u $ID0 chmod 666 $tfile_trunc ||
error "chmod failed for $tfile_trunc"
fi
$RUNAS_CMD -u $truncate_user $TRUNCATE $tfile_trunc 1048576 ||
error "truncate for file $tfile_trunc failed"
fi
# LDLM_ENQUEUE RPC (IT_CREAT intent) (setstripe)
$RUNAS_CMD -u $ID0 $LFS setstripe -c 1 -i 0 $tfile_creat ||
error "setstripe for file $tfile_creat failed"
# OST_FALLOCATE RPC (fallocate)
$RUNAS_CMD -u $ID0 $LFS setstripe -c 1 -i 0 $tfile_falloc ||
error "setstripe for file $tfile_falloc failed"
$RUNAS_CMD -u $ID0 fallocate -l 1M $tfile_falloc ||
error "fallocate for file $tfile_falloc failed"
check_ids_sync
# check IDs are set correctly
check_mdt_inode_ids $tfile_write $ID0 $ID0 $testdir_projid
check_ost_object_ids $tfile_write $ID0 $ID0 $testdir_projid
check_mdt_inode_ids $tfile_write2 $ID0 $ID0 0
check_ost_object_ids $tfile_write2 $ID0 $ID0 0
if $have_ost_punch_ids; then
check_mdt_inode_ids $tfile_trunc $ID0 $ID0 $testdir_projid
check_ost_object_ids $tfile_trunc $ID0 $ID0 $testdir_projid
fi
check_mdt_inode_ids $tfile_falloc $ID0 $ID0 $testdir_projid
check_ost_object_ids $tfile_falloc $ID0 $ID0 $testdir_projid
check_mdt_inode_ids $tfile_creat $ID0 $ID0 $testdir_projid
# move file to projdir should set PROJID from directory
# MDS_REINT RPC Client->MDS; OST_SETATTR RPC MDS->OST
mv $tfile_write ${testdir}/ || error "mv $tfile_write failed"
tfile_write=$testdir/${tfile}_write
# set explicit PROJID outside of projdir
# MDS_REINT RPC Client->MDS; OST_SETATTR RPC MDS->OST
$LFS project -p $testfile_projid $tfile_write2 ||
error "lfs project failed"
check_ids_sync
check_mdt_inode_ids $tfile_write $ID0 $ID0 $testdir_projid
check_ost_object_ids $tfile_write $ID0 $ID0 $testdir_projid
check_mdt_inode_ids $tfile_write2 $ID0 $ID0 $testfile_projid
check_ost_object_ids $tfile_write2 $ID0 $ID0 $testfile_projid
# move file to projdir should set new PROJID from directory
# MDS_REINT RPC Client->MDS; OST_SETATTR RPC MDS->OST
mv $tfile_write2 $projdir || error "mv $tfile_write2 failed"
tfile_write2=$projdir/${tfile}_write2
# chown should set new UID/GID
# MDS_REINT RPC Client->MDS; OST_SETATTR RPC MDS->OST
chown $ID1:$ID1 $tfile_write || error "chown $tfile_write failed"
check_ids_sync
check_mdt_inode_ids $tfile_write2 $ID0 $ID0 $testdir_projid
check_ost_object_ids $tfile_write2 $ID0 $ID0 $testdir_projid
check_mdt_inode_ids $tfile_write $ID1 $ID1 $testdir_projid
check_ost_object_ids $tfile_write $ID1 $ID1 $testdir_projid
}
run_test 75 "check uid/gid/projid are set on OST and MDT for various RPCs"
setup_75a() {
# Assumes that variables from test_75a are set
# Setup c0 (trusted) and c1 (tenant) nodemaps used by the clients
nodemap_test_setup
trap cleanup_75a EXIT
# configure tentant nodemap
do_facet mgs $LCTL nodemap_set_fileset --name $nm_tenant \
--fileset "/$fileset_nm" || error "Setting fileset failed"
do_facet mgs $LCTL nodemap_add_offset --name $nm_tenant \
--offset $offset_start --limit $offset_limit ||
error "cannot set offset for $nm_tenant"
do_facet mgs $LCTL nodemap_modify --name $nm_tenant \
--property map_mode=projid ||
error "cannot set offset for $nm_tenant"
# configure trusted nodemap
do_facet mgs $LCTL nodemap_modify --name $nm_trusted \
--property admin --value 1 || error "Setting admin=1 failed"
do_facet mgs $LCTL nodemap_modify --name $nm_trusted \
--property trusted --value 1 || error "Setting trusted=1 failed"
wait_nm_sync $nm_trusted trusted_nodemap
# create and set ownership for fileset dir of "nm_tenant"
$run_as_trusted mkdir -p $fileset_subdir ||
error "mkdir $fileset_subdir failed"
$run_as_trusted chown $((offset_start+ID0)) $fileset_subdir
# remount clients for nodemap changes to take effect.
# This mounts the trusted nodemap (c0) and tenant nodemap (c1)
export FILESET=/
for client in "${clients_arr[@]}"; do
zconf_umount_clients $client $MOUNT ||
error "unable to umount client ${clients_arr[0]}"
zconf_mount_clients $client $MOUNT $MOUNT_OPTS ||
error "unable to umount client ${clients_arr[0]}"
done
unset FILESET
wait_ssk
}
setup_namespace_75a() {
# Assumes that variables from test_75a are set
setup_tfiles_75a() {
local tenant_file=$1
local tenant_dir=$2
local offset=$3
$run_as_trusted "echo \"abc\" > ${fileset_subdir}/$tenant_file" ||
error "echo $tenant_file failed"
$run_as_trusted mkdir -p ${fileset_subdir}/$tenant_dir ||
error "mkdir $tenant_dir failed"
$run_as_trusted chmod 777 ${fileset_subdir}/$tenant_file \
${fileset_subdir}/$tenant_dir ||
error "chmod 777 $tenant_file and $tenant_dir failed"
$run_as_trusted chown \
$((offset+ID0)):$((offset+ID0)) \
${fileset_subdir}/$tenant_file \
${fileset_subdir}/$tenant_dir ||
error "chown $tenant_file and $tenant_dir failed"
}
# setup testfiles and testdirectories. *_trusted files/dirs are
# world-accessible, but become inaccessible once the id_check is enabled
$run_as_trusted "echo \"abc\" > ${fileset_subdir}/$tfile_trusted" ||
error "echo $tfile_trusted failed"
$run_as_trusted mkdir ${fileset_subdir}/$tdir_trusted ||
error "mkdir $tdir_trusted failed"
$run_as_trusted chmod 777 ${fileset_subdir}/$tdir_trusted \
${fileset_subdir}/$tfile_trusted ||
error "chmod 777 $tdir_trusted failed"
setup_tfiles_75a $tfile_tl $tdir_tl 100000
setup_tfiles_75a $tfile_tenant $tdir_tenant $offset_start
setup_tfiles_75a $tfile_tr $tdir_tr 300000
# DoM files
$run_as_trusted $LFS setstripe -E 1M -L mdt \
${fileset_subdir}/${tfile_trusted}_dom ||
error "setstripe ${tfile_trusted}_dom failed"
$run_as_trusted chmod 777 ${fileset_subdir}/${tfile_trusted}_dom ||
error "chmod 777 ${tfile_trusted}_dom failed"
$run_as_trusted $LFS setstripe -E 1M -L mdt \
${fileset_subdir}/${tfile_tenant}_dom ||
error "setstripe ${tfile_tenant}_dom failed"
$run_as_trusted chown \
$((offset_start+ID0)):$((offset_start+ID0)) \
${fileset_subdir}/${tfile_tenant}_dom ||
error "chown ${tfile_tenant}_dom failed"
# create a file used in write tests
$run_as_trusted "echo \"def\" > ${fileset_subdir}/$tf_write" ||
error "echo $tf_write failed"
$run_as_trusted chown \
$((offset_start+ID0)):$((offset_start+ID0)) \
${fileset_subdir}/$tf_write ||
error "chown $tf_write failed"
}
cleanup_75a() {
do_nodes $(all_mdts_nodes) \
$LCTL set_param mdt.*.enable_resource_id_check=0 ||
error "disabling resource id check on MDTs failed"
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_check=0 ||
error "disabling resource id check on OSTs failed"
nodemap_test_cleanup
for client in "${clients_arr[@]}"; do
zconf_umount_clients $client $MOUNT ||
error "unable to umount client $client"
zconf_mount_clients $client $MOUNT $MOUNT_OPTS ||
error "unable to umount client $client"
done
wait_ssk
}
test_75a() {
local offset_start=200000
local offset_limit=100000
local nm_trusted="c0"
local nm_tenant="c1"
local fileset_nm="${tdir}/${nm_tenant}_dir"
local fileset_subdir="${DIR}/${fileset_nm}"
local tfile_trusted="testfile_trusted"
local tfile_tenant="testfile_tenant"
local tdir_trusted="testdir_trusted"
local tdir_tenant="testdir_tenant"
# *_tl and *_tr files/dirs are set up such that their fs_ids are to the
# left and right of the tenant's offset range, respectively. This is to
# exercise both cases of nodemap_map_id() when mapping FS to client IDs.
local tfile_tl="testfile_tenant_left"
local tdir_tl="testdir_tenant_left"
local tfile_tr="testfile_tenant_right"
local tdir_tr="testdir_tenant_right"
local tf_write="testf_write"
local tf="testfile"
local client_trusted
local run_as_tenant
local have_dom_falloc=true
local out
# This test checks that the enable_resource_id_check flag works
# correctly by having a tenant accessing squashed files.
# Without this check, tenants are able to access such files
# that have world-accessible permissions.
# With the flag enabled, this is no longer possible.
# check that enable_resource_id_check flag exists
do_facet mds $LCTL get_param -n mdt.*.enable_resource_id_check ||
skip "MDS does not have the enable_resource_id_check flag"
do_facet ost $LCTL get_param -n obdfilter.*.enable_resource_id_check ||
skip "OSS does not have the enable_resource_id_check flag"
# need two clients to continue
(( $CLIENTCOUNT >= 2 )) || skip "need at least two clients"
if $SHARED_KEY; then
skip "need non-shared key for this test"
fi
# assign clients and helper routines
client_trusted=${clients_arr[0]}
client_tenant=${clients_arr[1]}
run_as_tenant="do_node $client_tenant $RUNAS_CMD -u $ID0"
run_as_trusted="do_node $client_trusted"
check_fallocate_supported mds1 || have_dom_falloc=false
setup_75a
do_nodes $(all_mdts_nodes) \
$LCTL set_param mdt.*.enable_resource_id_check=0 ||
error "disabling resource id check on MDTs failed"
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_check=0 ||
error "disabling resource id check on OSTs failed"
report_client_view_75a() {
# LU-18569 skip ls -l on ubuntu clients to investigate failures
[[ "$CLIENT_OS_ID_LIKE" =~ "ubuntu" ]] && return
echo "Trusted view:"
$run_as_trusted ls -al $fileset_subdir
echo "------------------------------"
echo "Tenant view:"
$run_as_tenant ls -al $MOUNT
}
75a_drop_tenant_cache() {
do_node $client_tenant \
"sync ; echo 3 > /proc/sys/vm/drop_caches"
}
75a_op_test() {
local test_cmd="$run_as_tenant $1"
local test_success=${2:-true}
if $test_success; then
$test_cmd || error "$1 failed"
else
$test_cmd && error "$1 should've failed"
fi
}
75a_read_test() {
local test_cmd="$run_as_tenant $1"
local test_success=${2:-true}
local expected=${3:-"def"}
local out
if $test_success; then
out=$($test_cmd) || error "$1 failed"
echo $out
[[ $out == $expected ]] ||
error "read $expected for $1 incorrect"
else
$test_cmd && error "$1 should've failed"
fi
}
75a_getxattr_test() {
local test_cmd="$run_as_tenant getfattr -n user.abc $1"
local test_success=${2:-true}
local expected=${3:-"\"def\""}
local out
if $test_success; then
out=$($test_cmd | awk -F'=' '/user.abc/ {print $2}') ||
error "$1 failed"
echo $out
[[ $out == $expected ]] ||
error "getxattr $expected for $1 incorrect"
else
$test_cmd && error "$1 should've failed"
fi
}
# Setup testrun 1
setup_namespace_75a
report_client_view_75a
# Testrun 1 begins (check disabled)
# 1. write to files
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_trusted" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tl" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tenant" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tr" true
75a_drop_tenant_cache
# 2. read from files
75a_read_test "cat ${MOUNT}/$tfile_trusted" true
75a_read_test "cat ${MOUNT}/$tfile_tl" true
75a_read_test "cat ${MOUNT}/$tfile_tenant" true
75a_read_test "cat ${MOUNT}/$tfile_tr" true
75a_drop_tenant_cache
# 3. create files in various dirs
75a_op_test "touch ${MOUNT}/${tdir_trusted}/$tf" true
75a_op_test "touch ${MOUNT}/${tdir_tl}/$tf" true
75a_op_test "touch ${MOUNT}/${tdir_tenant}/$tf" true
75a_op_test "touch ${MOUNT}/${tdir_tr}/$tf" true
# 4. soft and hard links
75a_op_test "ln ${MOUNT}/$tfile_trusted \
${MOUNT}/${tfile_trusted}_hlink" true
75a_op_test "ln -s ${MOUNT}/$tfile_trusted \
${MOUNT}/${tfile_trusted}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tl \
${MOUNT}/${tfile_tl}_hlink" true
75a_op_test "ln -s ${MOUNT}/$tfile_tl \
${MOUNT}/${tfile_tl}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tenant \
${MOUNT}/${tfile_tenant}_hlink" true
75a_op_test "ln -s ${MOUNT}/$tfile_tenant \
${MOUNT}/${tfile_tenant}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tr \
${MOUNT}/${tfile_tr}_hlink" true
75a_op_test "ln -s ${MOUNT}/$tfile_tr \
${MOUNT}/${tfile_tr}_slink" true
75a_read_test "cat ${MOUNT}/${tfile_trusted}_hlink" true
75a_read_test "cat ${MOUNT}/${tfile_trusted}_slink" true
75a_read_test "cat ${MOUNT}/${tfile_tl}_hlink" true
75a_read_test "cat ${MOUNT}/${tfile_tl}_slink" true
75a_read_test "cat ${MOUNT}/${tfile_tenant}_hlink" true
75a_read_test "cat ${MOUNT}/${tfile_tenant}_slink" true
75a_read_test "cat ${MOUNT}/${tfile_tr}_hlink" true
75a_read_test "cat ${MOUNT}/${tfile_tr}_slink" true
75a_op_test "rm ${MOUNT}/*_hlink" true
75a_op_test "rm ${MOUNT}/*_slink" true
# 5. fallocate (zfs does not support pre-allocation via fallocate(2))
if [[ "$ost1_FSTYPE" == "ldiskfs" ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_trusted" true
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tl" true
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tenant" true
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tr" true
fi
# 6. truncate
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_trusted 524288" true
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tl 524288" true
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tenant 524288" true
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tr 524288" true
# 7. rename files (and back)
75a_op_test "mv ${MOUNT}/$tfile_trusted ${MOUNT}/${tfile_trusted}_" true
75a_op_test "mv ${MOUNT}/${tfile_trusted}_ ${MOUNT}/$tfile_trusted" true
75a_op_test "mv ${MOUNT}/$tfile_tl ${MOUNT}/${tfile_tl}_" true
75a_op_test "mv ${MOUNT}/${tfile_tl}_ ${MOUNT}/$tfile_tl" true
75a_op_test "mv ${MOUNT}/$tfile_tenant ${MOUNT}/${tfile_tenant}_" true
75a_op_test "mv ${MOUNT}/${tfile_tenant}_ ${MOUNT}/$tfile_tenant" true
75a_op_test "mv ${MOUNT}/$tfile_tr ${MOUNT}/${tfile_tr}_" true
75a_op_test "mv ${MOUNT}/${tfile_tr}_ ${MOUNT}/$tfile_tr" true
# 8. trigger setattr operation with "touch" (timestamp update)
75a_op_test "touch ${MOUNT}/$tfile_trusted" true
75a_op_test "touch ${MOUNT}/$tfile_tl" true
75a_op_test "touch ${MOUNT}/$tfile_tenant" true
75a_op_test "touch ${MOUNT}/$tfile_tr" true
# 9. xattr, set and get
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_trusted" true
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tl" true
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tenant" true
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tr" true
75a_getxattr_test ${MOUNT}/$tfile_trusted true
75a_getxattr_test ${MOUNT}/$tfile_tl true
75a_getxattr_test ${MOUNT}/$tfile_tenant true
75a_getxattr_test ${MOUNT}/$tfile_tr true
# 10. remove create files from tenant dirs
75a_op_test "rm ${MOUNT}/${tdir_trusted}/$tf" true
75a_op_test "rm ${MOUNT}/${tdir_tl}/$tf" true
75a_op_test "rm ${MOUNT}/${tdir_tenant}/$tf" true
75a_op_test "rm ${MOUNT}/${tdir_tr}/$tf" true
# 11. remove all tenant dirs
75a_op_test "rmdir ${MOUNT}/$tdir_trusted" true
75a_op_test "rmdir ${MOUNT}/$tdir_tl" true
75a_op_test "rmdir ${MOUNT}/$tdir_tenant" true
75a_op_test "rmdir ${MOUNT}/$tdir_tr" true
# 12. remove remaining tenant files from root
75a_op_test "rm ${MOUNT}/$tfile_trusted" true
75a_op_test "rm ${MOUNT}/$tfile_tl" true
75a_op_test "rm ${MOUNT}/$tfile_tenant" true
75a_op_test "rm ${MOUNT}/$tfile_tr" true
# 13. Data on MDT cases
if [[ "$mds1_FSTYPE" == "ldiskfs" && $have_dom_falloc == true ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/${tfile_trusted}_dom" true
fi
75a_op_test "$TRUNCATE ${MOUNT}/${tfile_trusted}_dom 524288" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/${tfile_trusted}_dom" true
75a_drop_tenant_cache
75a_read_test "cat ${MOUNT}/${tfile_trusted}_dom" true
75a_op_test "rm ${MOUNT}/${tfile_trusted}_dom" true
if [[ "$mds1_FSTYPE" == "ldiskfs" && $have_dom_falloc == true ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/${tfile_tenant}_dom" true
fi
75a_op_test "$TRUNCATE ${MOUNT}/${tfile_tenant}_dom 524288" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/${tfile_tenant}_dom" true
75a_drop_tenant_cache
75a_read_test "cat ${MOUNT}/${tfile_tenant}_dom" true
75a_op_test "rm ${MOUNT}/${tfile_tenant}_dom" true
report_client_view_75a
do_nodes $(all_mdts_nodes) \
$LCTL set_param mdt.*.enable_resource_id_check=1 ||
error "enabling resource id check on MDTs failed"
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_check=1 ||
error "enabling resource id check on OSTs failed"
# Setup testrun 2
setup_namespace_75a
report_client_view_75a
# Testrun 2 begins (check enabled)
# 1. write to files
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_trusted" false
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tl" false
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tenant" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/$tfile_tr" false
75a_drop_tenant_cache
# 2. read from files
75a_read_test "cat ${MOUNT}/$tfile_trusted" false
75a_read_test "cat ${MOUNT}/$tfile_tl" false
75a_read_test "cat ${MOUNT}/$tfile_tenant" true
75a_read_test "cat ${MOUNT}/$tfile_tr" false
75a_drop_tenant_cache
# 3. create files
75a_op_test "touch ${MOUNT}/${tdir_trusted}/$tf" false
75a_op_test "touch ${MOUNT}/${tdir_tl}/$tf" false
75a_op_test "touch ${MOUNT}/${tdir_tenant}/$tf" true
75a_op_test "touch ${MOUNT}/${tdir_tr}/$tf" false
# 4. soft and hard links (cannot create hard links but soft links)
75a_op_test "ln ${MOUNT}/$tfile_trusted \
${MOUNT}/${tfile_trusted}_hlink" false
75a_op_test "ln -s ${MOUNT}/$tfile_trusted \
${MOUNT}/${tfile_trusted}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tl \
${MOUNT}/${tfile_tl}_hlink" false
75a_op_test "ln -s ${MOUNT}/$tfile_tl \
${MOUNT}/${tfile_tl}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tenant \
${MOUNT}/${tfile_tenant}_hlink" true
75a_op_test "ln -s ${MOUNT}/$tfile_tenant \
${MOUNT}/${tfile_tenant}_slink" true
75a_op_test "ln ${MOUNT}/$tfile_tr \
${MOUNT}/${tfile_tr}_hlink" false
75a_op_test "ln -s ${MOUNT}/$tfile_tr \
${MOUNT}/${tfile_tr}_slink" true
# can only read soft-links pointing to permitted files
75a_read_test "cat ${MOUNT}/${tfile_trusted}_slink" false
75a_read_test "cat ${MOUNT}/${tfile_tl}_slink" false
75a_read_test "cat ${MOUNT}/${tfile_tenant}_slink" true
75a_read_test "cat ${MOUNT}/${tfile_tr}_slink" false
# can remove all links created by tenant
75a_op_test "rm ${MOUNT}/${tfile_trusted}_slink" true
75a_op_test "rm ${MOUNT}/${tfile_tl}_slink" true
75a_op_test "rm ${MOUNT}/${tfile_tenant}_slink" true
75a_op_test "rm ${MOUNT}/${tfile_tr}_slink" true
75a_op_test "rm ${MOUNT}/${tfile_tenant}_hlink" true
# 5. fallocate (only on ldiskfs, zfs does not support pre-allocation)
if [[ "$ost1_FSTYPE" == "ldiskfs" ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_trusted" false
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tl" false
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tenant" true
75a_op_test "fallocate -l 1M ${MOUNT}/$tfile_tr" false
fi
# 6. truncate
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_trusted 524288" false
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tl 524288" false
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tenant 524288" true
75a_op_test "$TRUNCATE ${MOUNT}/$tfile_tr 524288" false
# 7. rename files (and back)
75a_op_test "mv ${MOUNT}/$tfile_trusted \
${MOUNT}/${tfile_trusted}_" false
75a_op_test "mv ${MOUNT}/$tfile_tl ${MOUNT}/${tfile_tl}_" false
75a_op_test "mv ${MOUNT}/$tfile_tenant ${MOUNT}/${tfile_tenant}_" true
75a_op_test "mv ${MOUNT}/${tfile_tenant}_ ${MOUNT}/$tfile_tenant" true
75a_op_test "mv ${MOUNT}/$tfile_tr ${MOUNT}/${tfile_tr}_" false
# 8. trigger setattr operation with "touch" (timestamp update)
75a_op_test "touch ${MOUNT}/$tfile_trusted" false
75a_op_test "touch ${MOUNT}/$tfile_tl" false
75a_op_test "touch ${MOUNT}/$tfile_tenant" true
75a_op_test "touch ${MOUNT}/$tfile_tr" false
# 9. xattr, set and get
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_trusted" false
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tl" false
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tenant" true
75a_op_test "setfattr -n user.abc -v def ${MOUNT}/$tfile_tr" false
75a_getxattr_test ${MOUNT}/$tfile_trusted false
75a_getxattr_test ${MOUNT}/$tfile_tl false
75a_getxattr_test ${MOUNT}/$tfile_tenant true
75a_getxattr_test ${MOUNT}/$tfile_tr false
# 10. remove create files from tenant dirs
75a_op_test "rm ${MOUNT}/${tdir_tenant}/$tf" true
# 11. attempt to remove all tenant dirs
75a_op_test "rmdir ${MOUNT}/$tdir_trusted" false
75a_op_test "rmdir ${MOUNT}/$tdir_tl" false
75a_op_test "rmdir ${MOUNT}/$tdir_tenant" true
75a_op_test "rmdir ${MOUNT}/$tdir_tr" false
# 12. attempt to remove remaining tenant files from root
75a_op_test "rm ${MOUNT}/$tfile_trusted" false
75a_op_test "rm ${MOUNT}/$tfile_tl" false
75a_op_test "rm ${MOUNT}/$tfile_tenant" true
75a_op_test "rm ${MOUNT}/$tfile_tr" false
# 13. Data on MDT cases
if [[ "$mds1_FSTYPE" == "ldiskfs" && $have_dom_falloc == true ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/${tfile_trusted}_dom" \
false
fi
75a_op_test "$TRUNCATE ${MOUNT}/${tfile_trusted}_dom 524288" false
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/${tfile_trusted}_dom" false
75a_read_test "cat ${MOUNT}/${tfile_trusted}_dom" false
75a_op_test "rm ${MOUNT}/${tfile_trusted}_dom" false
if [[ "$mds1_FSTYPE" == "ldiskfs" && $have_dom_falloc == true ]]; then
75a_op_test "fallocate -l 1M ${MOUNT}/${tfile_tenant}_dom" true
fi
75a_op_test "$TRUNCATE ${MOUNT}/${tfile_tenant}_dom 524288" true
75a_op_test "cp ${MOUNT}/$tf_write ${MOUNT}/${tfile_tenant}_dom" true
75a_drop_tenant_cache
75a_read_test "cat ${MOUNT}/${tfile_tenant}_dom" true
75a_op_test "rm ${MOUNT}/${tfile_tenant}_dom" true
report_client_view_75a
}
run_test 75a "test resource fs IDs against nodemap offset"
cleanup_75b() {
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_repair=1 ||
error "re-enable resource id repair on OSTs failed"
}
untag_ost_object_75b() {
local file=$1
local fids=($($LFS getstripe $file | grep 0x))
local fid="${fids[3]}:${fids[2]}:0"
local objpath=$(ost_fid2_objpath ost1 $fid)
# stop all servers before modifying OST objects through debugfs
stopall || error "unable to stop"
# Untag OST object simulating the OST object inode if it was never
# tagged. Such OST objects miss UID/GID/PROJID (default to 0) and use
# the mode of precreated OST objects:
# (S_IFREG | S_ISUID | S_ISGID | S_ISVTX | 0666)
do_facet ost1 "$DEBUGFS -w -f /dev/stdin $(ostdevname 1) <<- EOF
sif $objpath mode 0107666
sif $objpath uid 0
sif $objpath gid 0
sif $objpath projid 0
EOF"
mountmgs || error "unable to start mgs"
mountmds || error "unable to start mds"
mountoss || error "unable to start oss"
for client in "${clients_arr[@]}"; do
zconf_mount_clients $client $MOUNT $MOUNT_OPTS ||
error "unable to mount client $client"
done
wait_ssk
}
test_75b() {
local testdir="${DIR}/$tdir"
local testfile="${testdir}/$tfile"
local unset_attr_mode="07666"
# check that enable_resource_id_check flag exists
do_facet ost $LCTL get_param -n obdfilter.*.enable_resource_id_repair ||
skip "OSS does not have the enable_resource_id_repair flag"
[[ "$ost1_FSTYPE" == ldiskfs ]] ||
skip "ldiskfs only test (using debugfs)"
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_repair=0 ||
error "disabling resource id repair on OSTs failed"
# setup
run_as_root="do_node ${clients_arr[0]}"
run_as_user="do_node ${clients_arr[0]} $RUNAS_CMD -u $ID0"
$LFS mkdir $testdir || error "mkdir $tdir failed"
chown $ID0:$ID0 $testdir || error "chown $testdir failed"
# 1. sanity check - striped files are unclaimed by default without IDs
$run_as_user $LFS setstripe -c 1 -i 0 $testfile ||
error "touch $testfile failed"
echo "Check OST object IDs (1) - should be unset after file create"
check_ost_object_ids $testfile 0 0 0 "$unset_attr_mode"
# 2. write to file and wait for full sync, IDs should be implicitly set
$run_as_user "dd if=/dev/zero of=$testfile bs=1M count=1 && sync" ||
error "dd+sync $testfile failed"
echo "Check OST object IDs (2) - should be set after writting to file"
check_ids_sync
check_ost_object_ids $testfile $ID0 $ID0 0 "0666"
# 3. untag OST object simulating the case of a never claimed OST object
echo "Check OST object IDs (3) - should be unset after untagging"
untag_ost_object_75b $testfile
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_repair=0 ||
error "disabling resource id repair on OSTs failed"
check_ost_object_ids $testfile 0 0 0 "$unset_attr_mode"
# 4. read from file, IDs remain unset
echo "Check OST object IDs (4) - should remain unset with read"
$run_as_root "sync; sync; echo 3 > /proc/sys/vm/drop_caches"
$run_as_user "dd of=/dev/null if=$testfile bs=1M count=1" ||
error "dd $testfile failed"
check_ids_sync
check_ost_object_ids $testfile 0 0 0 "$unset_attr_mode"
# 5. enable repair and read from file, IDs repair should be triggered
# Only UID and GID are valid during read, PROJID remains unset
do_nodes $(all_osts_nodes) \
$LCTL set_param obdfilter.*.enable_resource_id_repair=1 ||
error "enabling resource id repair on OSTs failed"
stack_trap cleanup_75b EXIT
echo "Check OST object IDs (5) - should be set after repair due to read"
$run_as_root "sync; sync; echo 3 > /proc/sys/vm/drop_caches"
$run_as_user "dd of=/dev/null if=$testfile bs=1M count=1" ||
error "dd $testfile failed"
# wait for 10 seconds for repair thread to tag object
sleep 10
check_ost_object_ids $testfile $ID0 $ID0 0 "01666"
# 6. set projid on directory - all IDs should be set
echo "Check OST object IDs (6) - should be set after setting projid"
$LFS project -s -p 42 $testdir
check_ids_sync
check_ost_object_ids $testfile $ID0 $ID0 42 "0666"
}
run_test 75b "test resource ID repair"
cleanup_76() {
# unmount client
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# reset and deactivate nodemaps, remount client
cleanup_local_client_nodemap
# remount client on $MOUNT_2
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} || error "remount failed"
fi
wait_ssk
}
test_76() {
local user=$(getent passwd $RUNAS_ID | cut -d: -f1)
local grp=grptest76
local grpid=5000
local nm=c0
(( $MDS1_VERSION >= $(version_code 2.16.53) )) ||
skip "need MDS >= 2.16.53 for suppgroup mapping"
do_nodes $(comma_list $(all_mdts_nodes)) \
$LCTL set_param mdt.*.identity_upcall=NONE
# create a specific group and add it as a supplementary group for $USER0
groupadd -g $grpid $grp
stack_trap "groupdel $grp" EXIT
usermod -aG $grp $user
stack_trap "gpasswd -d $user $grp" EXIT
stack_trap cleanup_76 EXIT
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# setup nodemap with offset
setup_local_client_nodemap $nm 1 1
do_facet mgs $LCTL nodemap_add_offset --name $nm \
--offset 100000 --limit 200000 ||
error "nodemap_add_offset failed"
wait_nm_sync $nm offset
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed"
wait_ssk
# Create directory from client part of the nodemap, as root,
# and set its group membership to $grpid.
# This is going to be mapped on server side.
$LFS mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
chgrp -v $grp $DIR/$tdir || error "chgrp $DIR/$tdir failed"
chmod -v 0770 $DIR/$tdir || error "chmod $DIR/$tdir failed"
ls -ld $DIR/$tdir
cancel_lru_locks
# access as $USER0, should work because it has $grpid as a supp group
# and it is properly mapped on server side
$RUNAS -G$grpid ls -l $DIR/$tdir ||
error "ls -l $DIR/$tdir as $user failed"
$RUNAS -G$grpid touch $DIR/$tdir/fileA ||
error "touch $DIR/$tdir/fileA as $user failed"
}
run_test 76 "suppgroups and gid mapping"
test_77() {
local squash=100
local nm=c0
(( $MDS1_VERSION >= $(version_code 2.16.54) )) ||
skip "Need MDS version >= 2.16.54 for proper root offsetting"
do_nodes $(comma_list $(all_mdts_nodes)) \
$LCTL set_param mdt.*.identity_upcall=NONE
stack_trap cleanup_local_client_nodemap_with_mounts EXIT
# create dir before nodemap create
$LFS mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# setup nodemap with offset
setup_local_client_nodemap $nm 1 0
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_uid --value $squash ||
error "Setting squash_uid=$squash on $nm failed"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_gid --value $squash ||
error "Setting squash_gid=$squash on $nm failed"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_projid --value $squash ||
error "Setting squash_projid=$squash on $nm failed"
do_facet mgs $LCTL nodemap_add_offset --name $nm \
--offset 100000 --limit 200000 ||
error "nodemap_add_offset failed"
wait_nm_sync $nm offset
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed"
wait_ssk
# create a file as root...
touch $DIR/$tdir/fileA
# the owner:group ids read back should be 0:0
ls -ln $DIR/$tdir/fileA
[[ $(stat -c "%u:%g" $DIR/$tdir/fileA) == "0:0" ]] ||
error "bad owner/group for root file"
}
run_test 77 "root offsetting"
function parse_nodemap_stats() {
local awkcmd
awkcmd='/open/ {ropen=$2}
/close/ {rclose=$2}
/mknod/ {mknod=$2}
/link/ {link=$2}
/unlink/ {unlink=$2}
/mkdir/ {mkdir=$2}
/rmdir/ {rmdir=$2}
/rename/ {rename=$2}
/getattr/ {getattr=$2}
/setattr/ {setattr=$2}
/getxattr/ {getxattr=$2}
/setxattr/ {setxattr=$2}
/statfs/ {statfs=$2}
/sync/ {sync=$2}
/samedir_rename/ {samedir_rename=$2}
/parallel_rename_file/ {parallel_rename_file=$2}
/parallel_rename_dir/ {parallel_rename_dir=$2}
/crossdir_rename/ {crossdir_rename=$2}
/rename_trylocks/ {rename_trylocks=$2}
/read_bytes/ {read_bytes=$2}
/write_bytes/ {write_bytes=$2}
/read/ {rread=$2}
/write/ {rwrite=$2}
/punch/ {punch=$2}
/migrate/ {migrate=$2}
/fallocate/ {fallocate=$2}
END {print \
"[OPEN]=" ropen, \
"[CLOSE]=" rclose, \
"[MKNOD]=" mknod, \
"[LINK]=" link, \
"[UNLINK]=" unlink, \
"[MKDIR]=" mkdir, \
"[RMDIR]=" rmdir, \
"[RENAME]=" rename, \
"[GETATTR]=" getattr, \
"[SETATTR]=" setattr, \
"[GETXATTR]=" getxattr, \
"[SETXATTR]=" setxattr, \
"[STATFS]=" statfs, \
"[SYNC]=" sync, \
"[SAMEDIR_RENAME]=" samedir_rename, \
"[PARALLEL_RENAME_FILE]=" parallel_rename_file, \
"[PARALLEL_RENAME_DIR]=" parallel_rename_dir, \
"[CROSSDIR_RENAME]=" crossdir_rename, \
"[RENAME_TRYLOCKS]=" rename_trylocks, \
"[READ_BYTES]=" read_bytes, \
"[WRITE_BYTES]=" write_bytes, \
"[READ]=" rread, \
"[WRITE]=" rwrite, \
"[PUNCH]=" punch, \
"[MIGRATE]=" migrate, \
"[FALLOCATE]=" fallocate }'
do_facet $1 $LCTL get_param -n nodemap.${2}.*_stats |
awk "$awkcmd"
}
cleanup_78() {
local sk_unique_nm=${1:-false}
if $SHARED_KEY; then
export SK_UNIQUE_NM=$sk_unique_nm
zconf_umount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
zconf_mount_clients $CLIENTS $MOUNT ||
error "unable to umount clients $CLIENTS"
wait_ssk
fi
}
test_78() {
local activedefault
local td=$DIR/$tdir
declare -A stats
(( $MGS_VERSION >= $(version_code 2.16.54) )) ||
skip "nodemap stats need 2.16.54+"
test_mkdir -i0 -c1 $td || error "can't mkdir $td"
chmod a+rwx $td || error "can't chmod"
$LFS setstripe -i0 -c1 $td || error "can't set def striping"
stack_trap cleanup_78 EXIT
# make sure servers are in a privileged nodemap (default here)
do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 1
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property admin --value 0"
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 1
stack_trap "do_facet mgs $LCTL nodemap_modify --name default \
--property trusted --value 0"
wait_nm_sync default trusted_nodemap
activedefault=$(do_facet mgs $LCTL get_param -n nodemap.active)
(( $activedefault == 1 )) || {
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
stack_trap cleanup_active EXIT
}
do_facet mgs $LCTL nodemap_add c0
stack_trap "do_facet mgs $LCTL nodemap_del c0"
do_facet mgs $LCTL nodemap_add c1
stack_trap "do_facet mgs $LCTL nodemap_del c1"
local client_ip=$(host_nids_address ${clients_arr[0]} $NETTYPE)
local client_nid=$(h2nettype $client_ip)
echo "add client ${clients_arr[0]} with $client_ip"
do_facet mgs $LCTL nodemap_add_range \
--name c0 --range $client_nid ||
error "Add range $client_nid to c0 failed rc = $?"
$LCTL nodemap_modify --name c0 --property admin --value 1
$LCTL nodemap_modify --name c0 --property trusted --value 1
wait_nm_sync c0 trusted_nodemap
(( num_clients > 1 )) && {
client_ip=$(host_nids_address ${clients_arr[1]} $NETTYPE)
client_nid=$(h2nettype $client_ip)
echo "add client ${clients_arr[1]} with $client_ip"
do_facet mgs $LCTL nodemap_add_range \
--name c1 --range $client_nid ||
error "Add range $client_nid to c1 failed rc = $?"
$LCTL nodemap_modify --name c1 --property admin --value 1
$LCTL nodemap_modify --name c1 --property trusted --value 1
wait_nm_sync c1 trusted_nodemap
}
cleanup_78 true
# clear lru before IOs, as clients have been moved to a nodemap
do_nodes $(comma_list $clients) $LCTL set_param \
ldlm.namespaces.$FSNAME-MDT*.lru_size=clear
echo "stats before test"
do_facet mds1 "$LCTL get_param nodemap.c0.exports"
do_facet mds1 "$LCTL get_param nodemap.c0.md_stats"
do_facet ost1 "$LCTL get_param nodemap.c0.dt_stats"
(( num_clients > 1 )) && {
do_facet mds1 "$LCTL get_param nodemap.c1.exports"
do_facet mds1 "$LCTL get_param nodemap.c1.md_stats"
do_facet ost1 "$LCTL get_param nodemap.c1.dt_stats"
}
do_node ${clients_arr[0]} \
"dd if=/dev/zero of=$td/$tfile bs=1k count=1 conv=fsync"
(( num_clients > 1 )) &&
do_node ${clients_arr[1]} \
"dd if=/dev/zero of=$td/$tfile-2 bs=1k count=1 conv=fsync"
do_node ${clients_arr[0]} "rm -rf $td/*"
ls -lR $td
echo "stats after test"
do_facet mds1 "$LCTL get_param nodemap.c0.md_stats"
do_facet ost1 "$LCTL get_param nodemap.c0.dt_stats"
eval stats=($(parse_nodemap_stats mds1 c0))
(( ${stats[OPEN]} >= 1 && ${stats[CLOSE]} >= 1 &&
${stats[UNLINK]} >= 1 && ${stats[GETATTR]} >= 1 )) || {
do_facet mds2 "$LCTL get_param nodemap.c0.md_stats"
do_facet mds3 "$LCTL get_param nodemap.c0.md_stats"
do_facet mds4 "$LCTL get_param nodemap.c0.md_stats"
error "unexpected stats in c0"
}
eval stats=($(parse_nodemap_stats ost1 c0))
(( ${stats[WRITE]} == 1 && ${stats[SYNC]} == 1 )) ||
do_facet ost1 "$LCTL get_param nodemap.c0.dt_stats"
(( num_clients > 1 )) && {
eval stats=($(parse_nodemap_stats mds1 c1))
do_facet mds1 "$LCTL get_param nodemap.c1.md_stats"
do_facet ost1 "$LCTL get_param nodemap.c1.dt_stats"
(( ${stats[OPEN]} >= 1 && ${stats[CLOSE]} >= 1 &&
${stats[GETATTR]} >= 1 )) ||
error "unexpected stats in c1"
eval stats=($(parse_nodemap_stats ost1 c1))
(( ${stats[WRITE]} == 1 && ${stats[SYNC]} == 1 )) ||
error "unexpected stats in c1"
}
return 0
}
run_test 78 "nodemap stats"
cleanup_79() {
# unmount client
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT failed"
fi
cleanup_unload_ssk nm0
# reset and deactivate nodemaps, remount client
do_facet mgs $LCTL nodemap_del nm0 || true
$LGSS_SK -l $SK_PATH/$FSNAME.key
cleanup_local_client_nodemap c0
# remount client on $MOUNT_2
if [ "$MOUNT_2" ]; then
mount_client $MOUNT2 ${MOUNT_OPTS} || error "remount failed"
fi
wait_ssk
}
test_79() {
client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
client_nid=$(h2nettype $client_ip)
local banprop
$SHARED_KEY || skip "Need shared key feature for this test"
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS version >= 2.17.50 for gss identification"
do_nodes $(comma_list $(all_mdts_nodes)) \
$LCTL set_param mdt.*.identity_upcall=NONE
stack_trap cleanup_79 EXIT
mds1_mdtcnt=$(do_facet mds1 $LCTL list_param mdt.* | wc -l)
$LFS mkdir -c1 -i0 $DIR/$tdir
$LFS mkdir -c1 -i0 $DIR/$tdir/c0
touch $DIR/$tdir/c0/this_is_c0
$LFS mkdir -c1 -i0 $DIR/$tdir/nm0
touch $DIR/$tdir/nm0/this_is_nm0
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# create nodemap c0, SSK key already created by test framework
setup_local_client_nodemap c0 1 1
do_facet mgs $LCTL nodemap_modify --name c0 \
--property gssonly_identification --value 1 &&
error "gssonly_identification on c0 with nid range should fail"
do_facet mgs $LCTL nodemap_del_range --name c0 --range $client_nid ||
error "del range on c0 failed"
do_facet mgs $LCTL nodemap_set_fileset --name c0 \
--fileset "/$tdir/c0" ||
error "set_fileset on c0 failed"
do_facet mgs $LCTL nodemap_modify --name c0 \
--property gssonly_identification --value 1 ||
error "setting gssonly_identification on c0 failed"
do_facet mgs $LCTL nodemap_add_range --name c0 --range $client_nid &&
error "add range on c0 with gssonly_identification shoud fail"
wait_nm_sync c0 gssonly_identification
do_facet mgs $LCTL get_param -R 'nodemap.*'
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed (1)"
wait_ssk
[[ -f $DIR/this_is_c0 ]] || error "failed to get c0"
# test banlist support with gss identification
banprop=$(do_facet mgs $LCTL get_param nodemap.c0.banlist)
if [[ -n $banprop ]]; then
do_facet mgs $LCTL nodemap_banlist_add --name c0 \
--range $client_nid ||
error "banlist_add on c0 failed"
wait_nm_sync c0 banlist
stack_trap "do_facet mgs $LCTL nodemap_banlist_del --name c0 \
--range $client_nid || true" EXIT
# check client access: should be blocked
cancel_lru_locks
ls $DIR && error "ls $DIR should fail"
cat $DIR/this_is_c0 && error "cat $DIR/this_is_c0 should fail"
do_facet mgs $LCTL nodemap_banlist_del --name c0 \
--range $client_nid
wait_nm_sync c0 banlist
cancel_lru_locks
ls $DIR || error "ls $DIR failed"
cat $DIR/this_is_c0 || error "cat $DIR/this_is_c0 failed"
fi
# unmount client
umount_client $MOUNT || error "umount $MOUNT failed"
# unload c0 key on client
keyctl show | grep lustre:$FSNAME | cut -c1-11 | sed -e 's/ //g;' |
xargs -IX keyctl revoke X
keyctl reap
# create nodemap nm0
do_facet mgs $LCTL nodemap_add nm0
do_facet mgs $LCTL nodemap_modify --name nm0 \
--property admin --value 1
do_facet mgs $LCTL nodemap_modify --name nm0 \
--property trusted --value 1
do_facet mgs $LCTL nodemap_set_fileset --name nm0 \
--fileset "/$tdir/nm0" ||
error "set_fileset on nm0 failed"
do_facet mgs $LCTL nodemap_modify --name nm0 \
--property gssonly_identification --value 1 ||
error "setting gssonly_identification on nm0 failed"
wait_nm_sync nm0 gssonly_identification
do_facet mgs $LCTL get_param -R 'nodemap.*'
# create ssk for nm0, stack_trap
generate_load_ssk nm0
# mount client, should see nm0 fileset
$MOUNT_CMD -o $MOUNT_OPTS $MGSNID:/$FSNAME $MOUNT ||
error "remount failed (2)"
wait_ssk
[[ -f $DIR/this_is_nm0 ]] || error "failed to get nm0"
do_facet mds1 $LCTL get_param nodemap.*.exports
count=$(do_facet mds1 $LCTL get_param -n nodemap.nm0.exports |
grep -c $client_nid)
(( count == mds1_mdtcnt )) ||
error "$count exps for $client_nid on nm0 ($mds1_mdtcnt) (1)"
# change unrelated nodemap property, just to refresh nodemap definitions
do_facet mgs $LCTL nodemap_modify --name c0 \
--property audit_mode --value 0 ||
error "setting audit_mode on c0 failed"
wait_nm_sync c0 audit_mode
do_facet mds1 $LCTL get_param nodemap.*.exports
count=$(do_facet mds1 $LCTL get_param -n nodemap.nm0.exports |
grep -c $client_nid)
(( count == mds1_mdtcnt )) ||
error "$count exps for $client_nid on nm0 ($mds1_mdtcnt) (2)"
# mount client on DIR2 with c0 key, should see c0 fileset
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$SK_PATH/nodemap/c0.key \
$MGSNID:/$FSNAME $MOUNT2 ||
error "remount failed (3)"
wait_ssk
[[ -f $DIR2/this_is_c0 ]] || error "failed to get c0 in $DIR2"
do_facet mds1 $LCTL get_param nodemap.*.exports
count=$(do_facet mds1 $LCTL get_param -n nodemap.c0.exports |
grep -c $client_nid)
(( count == mds1_mdtcnt )) ||
error "$count exps for $client_nid on nm0 ($mds1_mdtcnt) (3)"
# remount client on DIR, should still be part of nm0
umount_client $MOUNT || error "umount $MOUNT failed"
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$SK_PATH/nodemap/nm0.key \
$MGSNID:/$FSNAME $MOUNT ||
error "remount failed (4)"
wait_ssk
[[ -f $DIR/this_is_nm0 ]] || error "failed to get nm0 in $DIR"
do_facet mds1 $LCTL get_param nodemap.*.exports
count=$(do_facet mds1 $LCTL get_param -n nodemap.nm0.exports |
grep -c $client_nid)
(( count == mds1_mdtcnt )) ||
error "$count exps for $client_nid on nm0 ($mds1_mdtcnt) (4)"
}
run_test 79 "ssk for nodemap identification"
test_81a() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local fake_nid=1.1.1.1@tcp999
local nm=c0
local dynnm=c1
local header="test_81a $RANDOM"
local need_nm=0
local exp_cnt_orig
local exp_cnt_new
local banmsg
(( $MDS1_VERSION >= $(version_code 2.16.57) )) ||
skip "Need MDS version >= 2.16.57 for ban list support"
(( $MDS1_VERSION >= $(version_code 2.16.58) )) ||
need_nm=1
log $header
stack_trap cleanup_local_client_nodemap_with_mounts EXIT
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# create data before nodemap setup
$LFS mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
echo hi > $DIR/$tdir/$tfile || error "create $DIR/$tdir/$tfile failed"
do_facet mgs $LCTL nodemap_add $nm
do_facet mgs $LCTL nodemap_modify --name default \
--property admin=1
do_facet mgs $LCTL nodemap_modify --name default \
--property trusted=1
do_facet mgs $LCTL nodemap_activate 1
wait_nm_sync active
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_orig=$(do_facet mds1 "$LCTL get_param nodemap.default.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_orig != 0 )) ||
error "no exports for $client_nid found on default"
# check client access: should succeed
cancel_lru_locks
ls $DIR/$tdir || error "ls $DIR/$tdir failed (0)"
cat $DIR/$tdir/$tfile || error "cat $DIR/$tdir/$tfile failed (0)"
# add ban list to default nodemap
stack_trap "do_facet mgs $LCTL nodemap_banlist_del --name default \
--range $client_nid || true" EXIT
if (( need_nm == 0 )); then
do_facet mgs $LCTL nodemap_banlist_add --range 1.1.1.1@tcp999 ||
error "Setting banlist=1.1.1.1@tcp999 on default failed"
wait_nm_sync default banlist
do_facet mgs $LCTL nodemap_banlist_del --range 1.1.1.1@tcp999 ||
error "Removing banlist=1.1.1.1@tcp999 on default failed"
wait_nm_sync default banlist
fi
do_facet mgs $LCTL nodemap_banlist_add --name default \
--range $client_nid ||
error "Setting banlist=$client_nid on default failed"
wait_nm_sync default banlist
# check client access: should fail
cancel_lru_locks
ls $DIR/$tdir && error "ls $DIR/$tdir should fail (0)"
cat $DIR/$tdir/$tfile && error "cat $DIR/$tdir/$tfile should fail (0)"
# no nodemap can have a NID range that conflicts with default's banlist
do_facet mgs $LCTL nodemap_add_range \
--name $nm --range $client_nid &&
error "Add range $client_nid to $nm should fail"
do_facet mgs $LCTL nodemap_del $nm
do_facet mgs $LCTL nodemap_banlist_del --name default \
--range $client_nid ||
error "Deleting banlist=$client_nid on default failed"
# setup nodemap
setup_local_client_nodemap $nm 1 1
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_orig=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_orig != 0 )) ||
error "no exports for $client_nid found on $nm"
# check client access: should succeed
cancel_lru_locks
ls $DIR/$tdir || error "ls $DIR/$tdir failed (1)"
cat $DIR/$tdir/$tfile || error "cat $DIR/$tdir/$tfile failed (1)"
# add ban list
do_facet mgs $LCTL nodemap_banlist_add --name default \
--range $client_nid &&
error "Setting banlist=$client_nid on default should fail"
do_facet mgs $LCTL nodemap_banlist_add --name $nm --range $fake_nid &&
error "Setting banlist=$fake_nid on $nm should fail"
if (( need_nm == 0 )); then
do_facet mgs $LCTL nodemap_banlist_add --range $client_nid ||
error "Setting banlist=$client_nid on $nm failed (1)"
wait_nm_sync $nm banlist
do_facet mgs $LCTL nodemap_banlist_del --range $client_nid ||
error "Deleting banlist=$client_nid on $nm failed (1)"
wait_nm_sync $nm banlist
fi
do_facet mgs $LCTL nodemap_banlist_add --name $nm --range $client_nid ||
error "Setting banlist=$client_nid on $nm failed (2)"
wait_nm_sync $nm banlist
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $nm, expected $exp_cnt_orig"
# check client access: should fail
cancel_lru_locks
ls $DIR/$tdir && error "ls $DIR/$tdir should fail (1)"
cat $DIR/$tdir/$tfile && error "cat $DIR/$tdir/$tfile should fail (1)"
# del ban list
do_facet mgs $LCTL nodemap_banlist_del --name $nm --range $client_nid ||
error "Deleting banlist=$client_nid on $nm failed (2)"
wait_nm_sync $nm banlist
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $nm, expected $exp_cnt_orig"
# check client access: should succeed
cancel_lru_locks
ls $DIR/$tdir || error "ls $DIR/$tdir failed (2)"
cat $DIR/$tdir/$tfile || error "cat $DIR/$tdir/$tfile failed (2)"
# add ban list again
do_facet mgs $LCTL nodemap_banlist_add --name $nm --range $client_nid ||
error "Setting banlist=$client_nid on $nm failed"
wait_nm_sync $nm banlist
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $nm, expected $exp_cnt_orig"
# unmount while in ban list: should succeed
umount_client $MOUNT || error "umount $MOUNT failed (1)"
# remount while in ban list: should fail
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS &&
error "remount should fail (1)"
# del ban list again
do_facet mgs $LCTL nodemap_banlist_del --name $nm --range $client_nid ||
error "Deleting banlist=$client_nid on $nm failed"
wait_nm_sync $nm banlist
# remount
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed (1)"
wait_ssk
# check client access: should succeed
cancel_lru_locks
ls $DIR/$tdir || error "ls $DIR/$tdir failed (3)"
cat $DIR/$tdir/$tfile || error "cat $DIR/$tdir/$tfile failed (3)"
# the rest of the test cannot be executed with SSK, as we do not have
# a key for the dynamic nodemap
if $SHARED_KEY; then
return 0;
fi
# create dynamic nodemap
do_facet mds1 $LCTL nodemap_add -d -p $nm $dynnm ||
error "failed to create dynamic nodemap"
do_facet mds1 $LCTL nodemap_add_range --name $dynnm \
--range $client_nid ||
error "add_range on $dynnm failed"
# check nodemap exports, without remounting
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == 0 )) ||
error "found $exp_cnt_new exports for $client_nid on $nm"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$dynnm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $dynnm, expected $exp_cnt_orig"
# add ban list on dynamic nm
do_facet mds1 $LCTL nodemap_banlist_add --name $dynnm \
--range $client_nid ||
error "Setting banlist=$client_nid on $dynnm failed"
# check client access: should fail
cancel_lru_locks
ls $DIR/$tdir && error "ls $DIR/$tdir should fail (2)"
cat $DIR/$tdir/$tfile && error "cat $DIR/$tdir/$tfile should fail (2)"
# unmount while in ban list: should succeed
umount_client $MOUNT || error "umount $MOUNT failed (2)"
# remount while in ban list: should fail
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS &&
error "remount should fail (2)"
# del ban list on dynamic nodemap
do_facet mds1 $LCTL nodemap_banlist_del --name $dynnm \
--range $client_nid ||
error "Deleting banlist=$client_nid on $dynm failed"
# remount
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed (2)"
wait_ssk
# check nodemap exports
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt_new=$(do_facet mds1 "$LCTL get_param nodemap.$dynnm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt_new == exp_cnt_orig )) ||
error "found $exp_cnt_new exports for $client_nid on $dynnm, expected $exp_cnt_orig"
# check client access: should succeed
cancel_lru_locks
ls $DIR/$tdir || error "ls $DIR/$tdir failed (4)"
cat $DIR/$tdir/$tfile || error "cat $DIR/$tdir/$tfile failed (4)"
# console messages may be ratelimited on later iterations
if (( ONLY_REPEAT_ITER != 1 )); then
echo "console messages may be ratelimited on iterations"
return 0
fi
# check ban message in client console
banmsg=$(dmesg | awk -v pattern="$header" \
'$0 ~ pattern { marker=1 } \
/This client was banned by administrative request/ { \
if (marker) { print; exit } }')
[[ -n "$banmsg" ]] || error "no ban message in client console"
}
run_test 81a "nodemap ban list"
cleanup_81b() {
cleanup_local_client_nodemap_with_mounts
zconf_umount ${clients_arr[1]} $MOUNT ||
error "umount $MOUNT for ${clients_arr[1]} failed"
zconf_mount ${clients_arr[1]} $MOUNT ||
error "remount $MOUNT for ${clients_arr[1]} failed"
wait_ssk
}
test_81b() {
local client1_ip=$(host_nids_address ${clients_arr[0]} $NETTYPE)
local client1_nid=$(h2nettype $client1_ip)
local tf=$DIR/$tdir/$tfile
local mnt_opts=$MOUNT_OPTS
local client2_ip
local client2_nid
local nm=c0
local failed
local fid
(( num_clients >= 2 )) || skip "Need 2 clients"
(( $MDS1_VERSION >= $(version_code 2.16.57) )) ||
skip "Need MDS version >= 2.16.57 for ban list support"
stack_trap cleanup_81b EXIT
# create data before nodemap setup
$LFS mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
echo hi > $tf || error "create $tf failed"
fid=$(lfs path2fid $tf)
fid="${fid:1:-1}"
# setup nodemap
setup_local_client_nodemap $nm 1 1 ${clients_arr[0]}
client2_ip=$(host_nids_address ${clients_arr[1]} $NETTYPE)
client2_nid=$(h2nettype $client2_ip)
do_facet mgs $LCTL nodemap_add_range \
--name $nm --range $client2_nid ||
error "Add range $client2_nid to $nm failed"
do_facet mgs $LCTL nodemap_modify \
--name $nm --property deny_unknown --value 1 ||
error "deny_unknown=1 on $nm failed"
wait_nm_sync $nm deny_unknown
# 2nd client is also part of $nm, so need to remount with the key for it
if $SHARED_KEY; then
mnt_opts=${mnt_opts},skpath=$SK_PATH/nodemap/${nm}.key
fi
zconf_umount ${clients_arr[1]} $MOUNT ||
error "umount $MOUNT on ${clients_arr[1]} failed"
do_node ${clients_arr[1]} $MOUNT_CMD -o $mnt_opts \
$MGSNID:/$FSNAME $MOUNT ||
error "mount $MOUNT on ${clients_arr[1]} failed"
wait_ssk
# from 1st client, write to file and pause
rmultiop_start ${clients_arr[0]} $tf OP1024yY_c ||
error "multiop from ${clients_arr[0]} failed"
stack_trap "rmultiop_stop ${clients_arr[0]} || true" EXIT
# add 1st client to ban list
do_facet mgs $LCTL nodemap_banlist_add \
--name $nm --range $client1_nid ||
error "Setting banlist=$client1_nid on $nm failed"
wait_nm_sync $nm banlist
# from 2nd client, write to same file
rmultiop_start ${clients_arr[1]} $tf OP3yY_c ||
error "multiop from ${clients_arr[1]} failed"
rmultiop_stop ${clients_arr[1]}
# 1st client is still banned, but it should be able to close file
rmultiop_stop ${clients_arr[0]}
failed=$(do_node ${clients_arr[0]} dmesg | grep "mdc close failed" |
grep $fid)
[[ -z "$failed" ]] || error "client ${clients_arr[0]} failed to close"
}
run_test 81b "banned client does not block other"
test_82() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local tf=$DIR/$tdir/$tfile
local nm1=c0
local nm2=c1
(( $MDS1_VERSION >= $(version_code 2.16.58) )) ||
skip "Need MDS version >= 2.16.58 for export lock revoke"
if $SHARED_KEY; then
skip "Conflicting test with SSK"
fi
stack_trap cleanup_local_client_nodemap_with_mounts EXIT
stack_trap "cleanup_local_client_nodemap $nm2" EXIT
# create data before nodemap setup
$LFS mkdir -i 0 -c 1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
echo hi > $tf || error "create $tf failed"
chmod 600 $tf || error "chmod 600 $tf failed"
# setup nodemaps
setup_local_client_nodemap $nm2 1 1
do_facet mgs $LCTL nodemap_del_range \
--name $nm2 --range $client_nid ||
error "del range $client_nid to $nm2 failed"
setup_local_client_nodemap $nm1 1 1
# access test file
cancel_lru_locks
cat $tf || error "from $nm1, cat $tf failed"
# remove admin from nm1
do_facet mgs $LCTL nodemap_modify --name $nm1 \
--property admin --value 0 ||
error "modify admin=0 on $nm1 failed"
wait_nm_sync $nm1 admin_nodemap
# access test file, should now fail
cat $tf && error "cat $tf should fail"
# move client to other nodemap
do_facet mgs $LCTL nodemap_del_range \
--name $nm1 --range $client_nid ||
error "del range $client_nid to $nm1 failed"
do_facet mgs $LCTL nodemap_add_range \
--name $nm2 --range $client_nid ||
error "add range $client_nid to $nm2 failed"
wait_nm_sync $nm2 ranges
# access test file, should now work
cat $tf || error "from $nm2, cat $tf failed"
}
run_test 82 "export lock revoked after nodemap change"
test_83() {
local user=$(getent passwd $RUNAS_ID | cut -d: -f1)
local grp=grptest83
local grp2=grptest832
local grpid=5000
local grp2id=5001
local subd=subdir
(( $MDS1_VERSION >= $(version_code 2.16.58) )) ||
skip "Need MDS version >= 2.16.58 for suppgids in cross-MDT ops"
(( MDSCOUNT >= 2 )) || skip "needs >= 2 MDTs"
do_nodes $(comma_list $(all_mdts_nodes)) \
$LCTL set_param mdt.*.identity_upcall=NONE
$LFS mkdir -i1 -c1 $DIR/$tdir || error "mkdir $DIR/$tdir failed"
$LFS mkdir -i0 -c1 $DIR/$tdir/$subd ||
error "mkdir $DIR/$tdir/$subd failed"
touch $DIR/$tdir/$subd/$tfile ||
error "touch $DIR/$tdir/$subd/$tfile failed"
# create two groups and add them as supp groups for $USER0
groupadd -g $grpid $grp
groupadd -g $grp2id $grp2
stack_trap "groupdel $grp" EXIT
stack_trap "groupdel $grp2" EXIT
usermod -aG $grp $user
usermod -aG $grp2 $user
stack_trap "gpasswd -d $user $grp" EXIT
stack_trap "gpasswd -d $user $grp2" EXIT
chown root:$grp $DIR/$tdir || error "chown $DIR/$tdir failed"
chown -R root:$grp2 $DIR/$tdir/$subd ||
error "chown $DIR/$tdir/$subd failed"
chmod 770 $DIR/$tdir || error "chmod $DIR/$tdir failed"
chmod 770 $DIR/$tdir/$subd || error "chmod $DIR/$tdir/$subd failed"
chmod 660 $DIR/$tdir/$subd/$tfile ||
error "chmod $DIR/$tdir/$subd/$tfile failed"
# unmount and remount to purge cache
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
strack_trap "zconf_mount $HOSTNAME $MOUNT2" EXIT
fi
zconf_mount $HOSTNAME $MOUNT ||
error "unable to remount client"
wait_ssk
su - $USER0 -c "ls $DIR/$tdir/$subd/*" ||
error "ls $DIR/$tdir/$subd/* as $USER0 failed"
}
run_test 83 "Suppgids for cross-MDT ops"
test_84() {
local nm=c0
(( MDS1_VERSION > $(version_code 2.16.61) )) ||
skip "Need MDS version at least 2.16.61 for correct squashing"
mkdir -p $DIR/$tdir/$USER0
touch $DIR/$tdir/$USER0/fileA
chown -R $ID0:$ID0 $DIR/$tdir
chown $ID0:$ID1 $DIR/$tdir/$USER0/fileA
stack_trap cleanup_local_client_nodemap EXIT
setup_local_client_nodemap $nm 1 1
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_uid=$ID0 ||
error "cannot set squash_uid=$ID0 on $nm"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_gid=$ID0 ||
error "cannot set squash_gid=$ID0 on $nm"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property squash_projid=$ID0 ||
error "cannot set squash_projid=$ID0 on $nm"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property deny_unknown=1 ||
error "cannot set deny_unknown=1 on $nm"
wait_nm_sync $nm deny_unknown
$RUNAS_CMD -u $ID0 touch $DIR/$tdir/file01 ||
error "touch $DIR/$tdir/file01 failed"
$RUNAS_CMD -u $ID0 mkdir $DIR/$tdir/dir01 ||
error "mkdir $DIR/$tdir/dir01 failed"
$RUNAS_CMD -u $ID0 ls -l $DIR/$tdir/$USER0 ||
error "ls -l $DIR/$tdir/$USER0 failed"
$RUNAS_CMD -u $ID0 chown $ID0:$ID0 $DIR/$tdir/$USER0/fileA ||
error "chown $ID0:$ID0 $DIR/$tdir/$USER0/fileA failed"
}
run_test 84 "do not squash trusted ids"
test_85() {
local nm=c0
local val
(( MDS1_VERSION > $(version_code 2.16.61) )) ||
skip "Need MDS version at least 2.16.61 for correct squashing"
stack_trap cleanup_local_client_nodemap EXIT
setup_local_client_nodemap $nm 1 1
do_facet mgs $LCTL nodemap_modify --name $nm --property squash_uid=0 &&
error "setting squash_uid=0 on $nm should fail"
do_facet mgs $LCTL nodemap_modify --name $nm --property squash_gid=0 &&
error "setting squash_gid=0 on $nm should fail"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property deny_unknown=1 ||
error "cannot set deny_unknown=1 on $nm"
wait_nm_sync $nm deny_unknown
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.squash_uid)
(( val != 0 )) || error "squash_uid should not be 0 on $nm"
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.squash_gid)
(( val != 0 )) || error "squash_gid should not be 0 on $nm"
}
run_test 85 "forbid squashing to UID/GID 0"
check_contains() {
local val="$1"; shift
for role in "$@"; do
[[ "$val" =~ "$role" ]] ||
error "rbac should contain '$role', got '$val'"
done
}
check_not_contains() {
local val="$1"; shift
for role in "$@"; do
[[ "$val" =~ "$role" ]] &&
error "rbac should NOT contain '$role', got '$val'"
done
}
test_93() {
local nm=c0
local val
(( MGS_VERSION >= $(version_code 2.17.52) )) ||
skip "Need MGS >= 2.17.52 for incremental RBAC role updates"
stack_trap cleanup_local_client_nodemap EXIT
setup_local_client_nodemap $nm 1 1
# Start with only file_perms
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=file_perms ||
error "setting rbac file_perms failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
[[ "$val" == "file_perms" ]] ||
error "rbac should be 'file_perms', got '$val'"
# Add dne_ops
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=+dne_ops ||
error "incrementally adding dne_ops failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms dne_ops
# Add quota_ops
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=+quota_ops ||
error "incrementally adding quota_ops failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms dne_ops quota_ops
# Remove dne_ops
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=-dne_ops ||
error "incrementally removing dne_ops failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms quota_ops
check_not_contains "$val" dne_ops
# Add multiple roles
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=+byfid_ops,+chlg_ops ||
error "incrementally adding multiple roles failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms quota_ops byfid_ops chlg_ops
# Remove multiple roles
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=-file_perms,-quota_ops ||
error "incrementally removing multiple roles failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" byfid_ops chlg_ops
check_not_contains "$val" file_perms quota_ops
# Mixed add/remove
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=+file_perms,-chlg_ops ||
error "incrementally adding and removing roles failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms byfid_ops
check_not_contains "$val" chlg_ops
# Reset to none
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=none ||
error "setting rbac to none failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
[[ -z "$val" ]] || error "rbac should be empty (none), got '$val'"
# Set to all
do_facet mgs $LCTL nodemap_modify --name $nm \
--property rbac=all ||
error "setting rbac to all failed"
wait_nm_sync $nm rbac
val=$(do_facet mgs $LCTL get_param -n nodemap.$nm.rbac)
check_contains "$val" file_perms dne_ops quota_ops byfid_ops chlg_ops fscrypt_admin
}
run_test 93 "incremental RBAC role modifications"
clear_client_keyring() {
keyctl show | grep lustre | cut -c1-11 | sed -e 's/ //g;' |
xargs -IX keyctl unlink X 2>/dev/null || true
}
cleanup_100() {
local orig_sk_path="$1"
local test_key="$orig_sk_path/$FSNAME-test100*.key"
# Restore original SK_PATH
export SK_PATH="$orig_sk_path"
# Ensure client is unmounted
zconf_umount_clients $HOSTNAME $MOUNT 2>/dev/null || true
# Clear test keys from keyring on all nodes
do_nodes $(all_nodes) "keyctl show |
awk '/lustre/ { print \\\$1 }' | xargs -IX keyctl unlink X" \
2>/dev/null || true
# Remove test key files from all nodes
do_nodes $(all_nodes) "rm -f $test_key" 2>/dev/null ||
true
# Reload original key on servers before remounting client
# The test key overwrote original key in keyring with same description.
do_nodes $(all_server_nodes) \
"$LGSS_SK -l $orig_sk_path/$FSNAME.key >/dev/null 2>&1" || true
# Remount with original configuration
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "unable to remount client with original key"
wait_ssk
}
do_test_100() {
local fmt="$1"
local orig_sk_path="$2"
local test_key="$orig_sk_path/$FSNAME-test100${fmt:+-ascii}.key"
# Generate key: Create a new server-type SSK key for testing
$LGSS_SK -t server -f $FSNAME $fmt -w $test_key \
-d /dev/urandom -p 512 ||
error "failed to create server key (fmt='$fmt')"
# An ASCII key must carry the 'Lustre SSK v1.0' format header
if [[ "$fmt" == "-a" ]]; then
head -n1 $test_key | grep -q "^Lustre SSK v1.0" ||
error "ASCII key missing 'Lustre SSK v1.0' header"
fi
# Verify key was created as server type (no client, no prime)
local key_type=$($LGSS_SK -r $test_key | awk '/Type:/ {print $0}')
[[ "$key_type" =~ server ]] ||
error "server key should have server type, got: $key_type"
[[ ! "$key_type" =~ client ]] ||
error "server key should not have client type, got: $key_type"
# Verify no prime is present in server key
$LGSS_SK -r $test_key 2>/dev/null | grep -q "^Prime (p)" &&
error "server key should not have prime field"
# Distribute key: Propagate the key to all nodes
local nodes_list=$(all_nodes)
for lnode in ${nodes_list//,/ }; do
scp $test_key ${lnode}:$test_key ||
error "failed to copy key to $lnode"
done
# Load key: Load the server key on server nodes only
# (NOT on clients - client will load it automatically during mount)
do_nodes $(all_server_nodes) \
"$LGSS_SK -l $test_key >/dev/null 2>&1" ||
error "failed to load server key on servers"
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# Clear any existing keys from keyring on client
clear_client_keyring
# Mount client using skpath pointing to the server key
export SK_PATH=$test_key
# Capture mount output to verify prime generation message
local mount_output
mount_output=$(zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS 2>&1)
local mount_rc=$?
wait_ssk
if [ $mount_rc -ne 0 ]; then
# Restore original key on servers since test key overwrote it
do_nodes $(all_server_nodes) \
"$LGSS_SK -l $orig_sk_path/$FSNAME.key >/dev/null 2>&1" ||
true
export SK_PATH="$orig_sk_path"
error "mount failed with server key (fmt='$fmt'): $mount_output"
fi
# Verify the mount succeeded and prime generation occurred
echo "$mount_output" | grep -q "Generating DH parameters" ||
error "prime generation message not found in mount output"
# The on-the-fly rewrite must leave a complete client key on disk;
$LGSS_SK -r $test_key ||
error "rewritten key is incomplete after mount (fmt='$fmt')"
# Verify the key file was modified to client type with prime
local new_key_type=$($LGSS_SK -r $test_key | awk '/Type:/ {print $0}')
[[ "$new_key_type" =~ client ]] ||
error "client key should have client type, got: $new_key_type"
# Verify prime was generated (check if prime field exists)
$LGSS_SK -r $test_key 2>/dev/null | grep -q "^Prime (p)" ||
error "prime should be present in client key"
# Test basic filesystem operations to ensure mount is functional
# Verify the test file created before unmount is still accessible
[[ -f $DIR/$tdir/$tfile ]] ||
error "file not found after remount with auto-generated prime"
}
test_100() {
local orig_sk_path=$SK_PATH
local fmt
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
stack_trap "cleanup_100 $orig_sk_path" EXIT
# Create test file at start to verify filesystem continuity throughout
test_mkdir $DIR/$tdir
touch $DIR/$tdir/$tfile || error "failed to create initial test file"
# Run the mount-time prime-generation + key-rewrite path for both a
# binary and an ASCII server key.
for fmt in "" "-a"; do
do_test_100 "$fmt" "$orig_sk_path"
done
}
run_test 100 "SSK automatic prime generation, binary/ASCII server keys"
clear_keyring_101() {
# clear lustre keys from client keyring
keyctl show | awk '/lustre/ { print $1 }' | xargs -IX keyctl unlink X ||
true
}
test_101() {
local test_dir=${DIR}/$tdir
local binary_key=${test_dir}/test.binary.key
local ascii_key=${test_dir}/test.ascii.key
local ascii_key_attr=${test_dir}/key_attr.txt
local ascii_key2=${test_dir}/test.ascii2.key
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "cannot run this test in local mode"
# Create test directory
mkdir -p $test_dir || error "failed to create test directory"
# Generate a binary key first for comparison
echo "#1 Creating binary key"
$LGSS_SK -t client -f $FSNAME -w $binary_key -d /dev/urandom -p 512 ||
error "failed to create binary key"
# Generate ASCII-encoded key using -a option
echo "#2 Creating ASCII-encoded key"
$LGSS_SK -t client -f $FSNAME -a -w $ascii_key -d /dev/urandom \
-p 512 || error "failed to create ASCII-encoded key"
# Verify ASCII key has correct header
echo "#3 Verifying ASCII key format"
head -n1 $ascii_key | grep -q "^Lustre SSK v1.0" ||
error "ASCII key does not have correct header"
# Verify ASCII key is readable and shows same structure as binary
echo "#4 Reading ASCII key attributes"
$LGSS_SK -r $ascii_key > $ascii_key_attr
# Verify key contains expected fields
grep -q "^Version:" $ascii_key_attr ||
error "ASCII key missing Version field"
grep -q "^Type:" $ascii_key_attr ||
error "ASCII key missing Type field"
grep -q "^File system:" $ascii_key_attr ||
error "ASCII key missing File system field"
local fs1=$(awk '/File system:/ {print $3}' $ascii_key_attr)
# Modify ASCII key (should preserve ASCII format)
echo "#5 Modifying ASCII key"
$LGSS_SK -m $ascii_key -e 86400 || error "failed to modify ASCII key"
# Verify it's still ASCII format after modification
head -n1 $ascii_key | grep -q "^Lustre SSK v1.0" ||
error "ASCII key lost format after modification"
# Convert binary key to ASCII using modify with -a
echo "#6 Converting binary key to ASCII format"
cp $binary_key $ascii_key2
$LGSS_SK -a -m $ascii_key2 || error "failed to convert bin key to ASCII"
# Verify conversion worked
head -n1 $ascii_key2 | grep -q "^Lustre SSK v1.0" ||
error "binary to ASCII conversion failed"
# Verify both ASCII keys are readable and have same basic structure
echo "#7 Comparing ASCII key structures"
$LGSS_SK -r $ascii_key2 > $ascii_key_attr
local fs2=$(awk '/File system:/ {print $3}' $ascii_key_attr)
# Check created key and converted key have the same filesystem name
[[ $fs1 == $fs2 ]] || error "filesystem names differ: $fs1 vs $fs2"
echo "#8 load ASCII key into keyring"
clear_keyring_101
stack_trap clear_keyring_101 EXIT
$LGSS_SK -l $ascii_key || error "cannot load $ascii_key"
[[ $(keyctl show | awk '/lustre/ { print $7 }') == "lustre:$fs1" ]] ||
error "key $ascii_key not listed in keyring"
}
run_test 101 "lgss_sk -a and -l support for ascii-encoded SSK keys"
cleanup_102() {
local test_key=$1
# Unmount client
if is_mounted $MOUNT; then
umount_client $MOUNT || error "umount $MOUNT failed"
fi
# Clear test key from keyring on all nodes
do_nodes $(comma_list $(all_nodes)) "keyctl show |
awk '/lustre/ { print \\\$1 }' | xargs -IX keyctl unlink X" \
2>/dev/null || true
# Remove test key file from all nodes
do_nodes $(comma_list $(all_nodes)) \
"rm -f $test_key" 2>/dev/null || true
rm -f $MOUNT/.lgss 2>/dev/null || true
# Reload original key on servers
do_nodes $(comma_list $(all_server_nodes)) \
"$LGSS_SK -l $SK_PATH/$FSNAME.key" || true
# Remount client
zconf_mount $HOSTNAME $MOUNT || error "re-mount $MOUNT failed"
if [ "$MOUNT_2" ]; then
zconf_mount $HOSTNAME $MOUNT2 ||
error "remount $MOUNT2 failed"
fi
wait_ssk
}
test_102() {
local test_key=$SK_PATH/$FSNAME-$TESTNAME.key
local mount_key=$MOUNT/.lgss
local nodes=$(all_nodes)
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
stack_trap "cleanup_102 $test_key"
# Create test file to verify filesystem access
test_mkdir $DIR/$tdir || error "mkdir $DIR/$tdir failed"
touch $DIR/$tdir/$tfile || error "failed to create initial test file"
# Unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# Generate key to test automatic loading
$LGSS_SK -t server -f $FSNAME -w $test_key -d /dev/urandom -p 512 ||
error "failed to create client key"
# Verify the key file was created
[[ -s $test_key ]] || error "key file is empty"
# Distribute key to all nodes
for lnode in ${nodes//,/ }; do
scp $test_key ${lnode}:$test_key ||
error "failed to copy key to $lnode"
done
# Load key on servers, this overrides the key from test-framework
do_nodes $(comma_list $(all_server_nodes)) "$LGSS_SK -l $test_key" ||
error "failed to load test key on servers"
# Verify server key presence in keyring
do_nodes $(comma_list $(all_server_nodes)) \
"keyctl show | grep lustre" || error "no lustre keys loaded"
# Clear any existing keys from keyring on client
clear_client_keyring
# Mount should fail without .lgss key file and without skpath
echo "Mount client (1): $MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT"
$MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT &&
error "mount should have failed without .lgss key file"
# Generate client key and copy to mount point for automatic loading
$LGSS_SK -t client -m $test_key || error "failed to generate client key"
cp $test_key $mount_key || error "failed to copy key to mount point"
chmod 600 $mount_key || error "failed to set key permissions"
echo "Mount client (2): $MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT"
$MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT ||
error "unable to mount client with automatic .lgss key loading"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] || error "$DIR/$tdir/$tfile does not exist"
# Test remount to verify persistence of .lgss key loading
umount $MOUNT || error "unable to umount"
# Clear test key from keyring on all nodes
keyctl show | awk '/lustre/ { print $1 }' |
xargs -IX keyctl unlink X 2>/dev/null || true
echo "Mount client (3): $MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT"
$MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT ||
error "unable to mount client with automatic .lgss key loading"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] || error "$DIR/$tdir/$tfile does not exist"
}
run_test 102 "SSK automatic key loading from mount point"
cleanup_103() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local test_key="$SK_PATH/$FSNAME-test103.key"
# ensure client is unmounted
umount_client $MOUNT || true
# clear test key from keyring on all server nodes
do_nodes $(comma_list $(all_server_nodes)) "keyctl show |
grep lustre:$FSNAME:default: | cut -c1-11 | sed -e 's/ //g;' |
xargs -IX keyctl unlink X" || true
# clear any existing keys from keyring on client
clear_client_keyring
# Remove test key file from all nodes
do_nodes $(comma_list $(all_nodes)) "rm -f $test_key" ||
true
# reload test-framework key on servers
do_nodes $(comma_list $(all_server_nodes)) \
"$LGSS_SK -l $SK_PATH/$FSNAME.key -vvv" ||
error "failed to reload key on servers"
# check old exports have been gc'ed
wait_update_facet --verbose mds1 \
"$LCTL get_param nodemap.default.exports |
grep -c $client_nid" 0 120 || true
# Remount client
zconf_mount $HOSTNAME $MOUNT || error "re-mount $MOUNT failed"
if [[ "$MOUNT_2" ]]; then
zconf_mount $HOSTNAME $MOUNT2 ||
error "remount $MOUNT2 failed"
fi
wait_ssk
}
test_103() {
local test_key="$SK_PATH/$FSNAME-test103.key"
local timeout=60
local sleeppid
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS >= 2.17.50 for multiple similar keys"
stack_trap cleanup_103 EXIT
test_mkdir $DIR/$tdir || error "mkdir $DIR/$tdir failed"
touch $DIR/$tdir/$tfile || error "touch $DIR/$tdir/$tfile failed"
# generate new SSK key for same fs
$LGSS_SK -t server -f $FSNAME -w $test_key -d /dev/urandom -p 512 ||
error "failed to create SSK key"
# distribute new key to all nodes
local nodes_list=$(all_nodes)
for lnode in ${nodes_list//,/ }; do
scp $test_key ${lnode}:$test_key ||
error "failed to copy key to $lnode"
done
# load new key on servers with -s to not overwrite already existing key
do_nodes $(comma_list $(all_server_nodes)) \
"$LGSS_SK -l $test_key -s -vvv -x $timeout" ||
error "failed to load key on servers"
# start timer for key expiration
sleep $((timeout + 10)) &
sleeppid=$!
# unmount client completely
umount_client $MOUNT || error "umount $MOUNT failed (1)"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
# remount client: should work by using old key
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$SK_PATH/$FSNAME.key \
$MGSNID:/$FSNAME $MOUNT ||
error "remount failed (1)"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] ||
error "file $DIR/$tdir/$tfile does not exist (1)"
umount_client $MOUNT || error "umount $MOUNT failed (2)"
# clear any existing keys from keyring on client
clear_client_keyring
# remount client: should work by using new key
$LGSS_SK -t client -m $test_key || error "failed to generate client key"
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$test_key $MGSNID:/$FSNAME $MOUNT ||
error "remount failed (2)"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] ||
error "file $DIR/$tdir/$tfile does not exist (2)"
umount_client $MOUNT || error "umount $MOUNT failed (3)"
# clear any existing keys from keyring on client
clear_client_keyring
# remount with former key
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$SK_PATH/$FSNAME.key \
$MGSNID:/$FSNAME $MOUNT ||
error "remount failed (3)"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] ||
error "file $DIR/$tdir/$tfile does not exist (3)"
# wait for key expiration
wait $sleeppid
cancel_lru_locks
$LFS flushctx $DIR
# access with old key should fail as it expired on server side
[[ -f $DIR/$tdir/$tfile ]] &&
error "file $DIR/$tdir/$tfile should be inaccessible"
umount_client $MOUNT || error "umount $MOUNT failed (4)"
# clear any existing keys from keyring on client
clear_client_keyring
# remount client: should work by using new key
$LGSS_SK -t client -m $test_key || error "failed to generate client key"
$MOUNT_CMD -o $MOUNT_OPTS,skpath=$test_key $MGSNID:/$FSNAME $MOUNT ||
error "remount failed (4)"
wait_ssk
[[ -f $DIR/$tdir/$tfile ]] ||
error "file $DIR/$tdir/$tfile does not exist (4)"
}
run_test 103 "Multiple SSK keys on server side"
cleanup_104() {
local test_key=$1
local nm=$2
keyctl show
umount_client $MOUNT || true
umount_client $MOUNT2 || true
# clear all keys on client
clear_client_keyring
# remove key files and nodemap
rm -f ${test_key}*
do_facet mgs $LCTL nodemap_del $nm || true
# load original key back and remount client
$LGSS_SK -l $SK_PATH/$FSNAME.key ||
error "failed to load original key on client"
zconf_mount $HOSTNAME $MOUNT || error "re-mount $MOUNT failed"
if [[ "$MOUNT_2" ]]; then
zconf_mount $HOSTNAME $MOUNT2 ||
error "remount $MOUNT2 failed"
fi
wait_ssk
}
test_104() {
local test_key="${SK_PATH}/${FSNAME}-test${testnum}"
local mgs_key="${test_key}-mgs.key"
local server_key="${test_key}-server.key"
local server_key2="${test_key}-server2.key"
local client_key="${test_key}-client.key"
local nm=test_${testnum}
local key_cnt
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
# needs lgss_sk -s support for this test
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS >= 2.17.50 for multiple similar keys"
stack_trap "cleanup_104 $test_key $nm" EXIT
# clear all keys on client
clear_client_keyring
umount_client $MOUNT || error "umount client at $MOUNT failed"
if is_mounted $MOUNT2; then
umount_client $MOUNT2 || error "umount $MOUNT2 failed"
fi
do_facet mgs $LCTL nodemap_add $nm
# generate a key for each type for the same fs
$LGSS_SK -t mgs -f $FSNAME -w $mgs_key -n $nm -d /dev/urandom -p 512 ||
error "failed to create MGS key"
$LGSS_SK -t server -f $FSNAME -w $server_key -n $nm -d /dev/urandom \
-p 512 || error "failed to create server key"
$LGSS_SK -t server -f $FSNAME -w $server_key2 -n $nm -d /dev/urandom \
-p 512 || error "failed to create server key 2"
$LGSS_SK -t client -f $FSNAME -w $client_key -n $nm -d /dev/urandom \
-p 512 || error "failed to create client key"
# No need to distribute keys since this test only interacts with lgss_sk
# and the kernel keyring. Key loading, etc, is exercised in other tests.
# load all keys including with suffixes
$LGSS_SK -t mgs -l $mgs_key -vvv || error "failed to load MGS key (1)"
$LGSS_SK -t mgs -l $mgs_key -vvv -s ||
error "failed to load MGS key (2)"
$LGSS_SK -t server -l $server_key -vvv ||
error "failed to load server key (1)"
$LGSS_SK -t server -l $server_key -vvv -s ||
error "failed to load server key (2)"
# also use a different server key with same name
# remove must be able to distinguish keys later based on payload
$LGSS_SK -t server -l $server_key2 -vvv -s ||
error "failed to load server key (3)"
$LGSS_SK -t server -l $server_key2 -vvv -s ||
error "failed to load server key (4)"
$LGSS_SK -t client -l $client_key -vvv ||
error "failed to load client key"
# sanity check that all keys were loaded
key_cnt=$(keyctl show | grep lustre | wc -l)
(( key_cnt == 7 )) ||
error "wrong # keys in keyring after loading. Expected 7, got $key_cnt (1)"
# remove mgs keys
$LGSS_SK -R $mgs_key -vvv ||
error "failed to remove MGS key"
key_cnt=$(keyctl show | grep lustre | wc -l)
(( key_cnt == 5 )) ||
error "wrong # keys in keyring after removing MGS key. Expected 5, got $key_cnt (2)"
# remove client key
$LGSS_SK -R $client_key -vvv ||
error "failed to remove client keys"
key_cnt=$(keyctl show | grep lustre | wc -l)
(( key_cnt == 4 )) ||
error "wrong # keys in keyring after removing client key. Expected 4, got $key_cnt (3)"
# remove server keys
$LGSS_SK -R $server_key -vvv ||
error "failed to remove server keys"
key_cnt=$(keyctl show | grep lustre | wc -l)
(( key_cnt == 2 )) ||
error "wrong # keys in keyring after removing server key. Expected 2, got $key_cnt (4)"
$LGSS_SK -R $server_key2 -vvv ||
error "failed to remove server keys (2)"
key_cnt=$(keyctl show | grep lustre | wc -l)
(( key_cnt == 0 )) ||
error "wrong # keys in keyring after removing server key. Expected 0, got $key_cnt (5)"
}
run_test 104 "SSK key removal from keyring"
cleanup_105() {
local nm_nid=$1
local nm_gss=$2
# ensure client is unmounted
umount_client $MOUNT || true
# remove nodemaps
do_facet mgs $LCTL nodemap_del $nm_nid
cleanup_local_client_nodemap $nm_gss
# remount all clients
restore_mount $MOUNT
if [[ "$MOUNT_2" ]]; then
restore_mount $MOUNT2
fi
restore_to_default_flavor
}
test_105() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local nm_nid=nm0
local nm_gss=c0
local exp_cnt
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS >= 2.17.50 for sec change nm update"
stack_trap "cleanup_105 $nm_nid $nm_gss"
# deactivate SSK for now
remove_flavor_all
wait_flavor cli2mdt null
wait_flavor cli2ost null
# unmount all clients
cleanup_mount $MOUNT
if [[ "$MOUNT_2" ]]; then
cleanup_mount $MOUNT2
fi
# create c0 nodemap with gssonly, SSK key already created by t-f
setup_local_client_nodemap $nm_gss 1 1
do_facet mgs $LCTL nodemap_del_range \
--name $nm_gss --range $client_nid ||
error "del range $client_nid from $nm_gss failed"
do_facet mgs $LCTL nodemap_modify --name $nm_gss \
--property gssonly_identification --value 1 ||
error "setting gssonly_identification on $nm_gss failed"
wait_nm_sync $nm_gss gssonly_identification
# create nm0 nodemap, with regular NID range
setup_local_client_nodemap $nm_nid 1 1
wait_nm_sync $nm_nid trusted_nodemap
# remount client to take nodemap into account
zconf_mount_clients $HOSTNAME $MOUNT $MOUNT_OPTS ||
error "remount failed"
# check nodemap exports, should be in nm0 because flavor is null
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm_nid.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt > 0 )) ||
error "no exports for $client_nid on $nm_nid (1)"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm_gss.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt == 0 )) ||
error "$exp_cnt != 0 exports for $client_nid on $nm_gss (1)"
restore_to_default_flavor || error "restore $SK_FLAVOR flavor failed"
# check nodemap exports, should have switched to c0
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm_nid.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt == 0 )) ||
error "$exp_cnt != 0 exports for $client_nid on $nm_nid (2)"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm_gss.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt > 0 )) ||
error "no exports for $client_nid on $nm_gss (2)"
}
run_test 105 "update nodemap membership on flavor change"
cleanup_106() {
local nm=$1
# ensure client is unmounted
umount_client $MOUNT || true
clear_client_keyring
# clear key from keyring on all server nodes
do_nodes $(comma_list $(all_server_nodes)) "keyctl show |
grep lustre:$FSNAME:$nm | cut -c1-11 | sed -e 's/ //g;' |
xargs -IX keyctl unlink X" || true
# remove nodemap, will also remount client on first mount point
cleanup_local_client_nodemap $nm
if [[ "$MOUNT_2" ]]; then
restore_mount $MOUNT2
fi
}
test_106() {
local client_ip=$(host_nids_address $HOSTNAME $NETTYPE)
local client_nid=$(h2nettype $client_ip)
local nm=c0
local ssk=$SK_PATH/nodemap/$nm.key
local exp_cnt
$SHARED_KEY || skip "Need shared key feature for this test"
local_mode && skip "in local mode."
(( MDS1_VERSION >= $(version_code 2.17.50) )) ||
skip "Need MDS >= 2.17.50 for gssonly switch"
stack_trap "cleanup_106 $nm"
# unmount all clients
cleanup_mount $MOUNT
if [[ "$MOUNT_2" ]]; then
cleanup_mount $MOUNT2
fi
clear_client_keyring
# create c0 nodemap, with regular NID range
setup_local_client_nodemap $nm 1 1
wait_nm_sync $nm trusted_nodemap
# Load c0 key on all nodes
do_nodes $(comma_list $(all_nodes)) \
"$LGSS_SK -l $ssk >/dev/null 2>&1" ||
error "failed to load $ssk key"
# mount client now that c0 key is loaded, should be in c0 nodemap
$MOUNT_CMD -o user_xattr,flock $MGSNID:/$FSNAME $MOUNT ||
error "mount failed with $ssk"
# check nodemap exports, should be in c0
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt > 0 )) ||
error "no exports for $client_nid on $nm (1)"
do_facet mgs $LCTL nodemap_del_range \
--name $nm --range $client_nid ||
error "del range $client_nid from $nm failed"
do_facet mgs $LCTL nodemap_modify --name $nm \
--property gssonly_identification --value 1 ||
error "setting gssonly_identification on $nm failed"
wait_nm_sync $nm gssonly_identification
# check nodemap exports, should still be in c0
do_facet mds1 "$LCTL get_param nodemap.*.exports"
exp_cnt=$(do_facet mds1 "$LCTL get_param nodemap.$nm.exports |
grep MDT | grep -c $client_nid")
(( exp_cnt > 0 )) ||
error "no exports for $client_nid on $nm (2)"
}
run_test 106 "switch nodemap to gssonly"
unlink_sktest_keys() {
# Unlink our test keys from @u directly. List @u with `keyctl list @u`
# (not `keyctl show`, which walks the session chain and only reaches @u
# when pam_keyinit linked it - the very thing this test avoids relying
# on) and unlink with an explicit @u argument.
keyctl list @u 2>/dev/null | awk -F: '/lustre:sktest:/ { print $1 }' |
xargs -r -I{} keyctl unlink {} @u 2>/dev/null || true
}
cleanup_200() {
unlink_sktest_keys
rm -f $1
}
test_200() {
local test_key=$TMP/sk_load_key_perms.key
local perm
$SHARED_KEY || skip "Need shared key feature for this test"
# Regression for sk_load_key()'s keyctl_setperm() silently failing when
# the caller does not possess @u (the sudo / systemd / cron case - no
# pam_keyinit). Load a key in a fresh session with no @u link and assert
# its perms end up broadened to 0x3f3f3f3f, not the default 0x3f010000.
stack_trap "cleanup_200 $test_key" EXIT
# Self-contained server key - metadata is baked into the file, no MGS
# needed. Loading it creates one keyring entry: lustre:sktest:default.
$LGSS_SK -t server -f sktest -g 127.0.0.1@tcp \
-w $test_key -d /dev/urandom -p 512 ||
error "failed to create test key"
# Drop any stale key so add_key() creates a fresh one - an
# update-in-place would keep old perms and mask a regression.
unlink_sktest_keys
# `keyctl session -` runs lgss_sk in a new anonymous session keyring
# with no @u link - the same starting point sudo / systemd give.
keyctl session - $LGSS_SK -l $test_key ||
error "lgss_sk -l failed in fresh session keyring"
# Read the perm mask (column 5) from /proc/keys; we parse it rather
# than `keyctl search` because a buggy USR_VIEW-only key has no SEARCH
# perm and a search would not find it.
perm=$(awk '$9 ~ /^lustre:sktest:default:/ {print $5}' /proc/keys)
[[ -n "$perm" ]] ||
error "key lustre:sktest:default not found in /proc/keys"
[[ "$perm" == "3f3f3f3f" ]] || error \
"key perm=$perm, expected 3f3f3f3f - sk_load_key did not broaden perms"
}
run_test 200 "sk_load_key broadens SSK key perms without @u linked"
test_300() {
local principal="mock_iam_test"
local mount_opts=$(csa_add "$MOUNT_OPTS" "" "user_principal=$principal")
local client1=${clients_arr[0]}
log "Mount with user_principal=$principal"
zconf_umount_clients $client1 $MOUNT || true
zconf_mount_clients $client1 $MOUNT "$mount_opts" ||
error "mount failed"
do_node $client1 "mount | grep ' $MOUNT ' |
grep -q 'user_principal=$principal'" ||
error "user_principal=$principal not in opts on $client"
zconf_umount_clients $client1 $MOUNT || error "umount failed"
log "Mount with only user_principal (should fail)"
mount_opts=$(csa_add "$MOUNT_OPTS" "" "user_principal")
if zconf_mount_clients $client1 $MOUNT "$mount_opts"; then
zconf_umount_clients $client1 $MOUNT || true
error "mount with only -o user_principal succeeded"
else
log "Mount failed as expected with only -o user_principal"
fi
}
run_test 300 "test user_principal mount option parsing"
log "cleanup: ======================================================"
sec_unsetup() {
for ((num = 1; num <= $MDSCOUNT; num++)); do
if [[ "${identity_old[$num]}" == 1 ]]; then
switch_identity $num false || identity_old[$num]=$?
fi
done
$RUNAS_CMD -u $ID0 ls $DIR
$RUNAS_CMD -u $ID1 ls $DIR
}
sec_unsetup
complete_test $SECONDS
check_and_cleanup_lustre
exit_status