|
| 1 | +local t = require('luatest') |
| 2 | +local vtest = require('test.luatest_helpers.vtest') |
| 3 | +local vutil = require('vshard.util') |
| 4 | +local fio = require('fio') |
| 5 | + |
| 6 | +local g = t.group('router_ssl') |
| 7 | +local cfg_template = { |
| 8 | + sharding = { |
| 9 | + { |
| 10 | + replicas = { |
| 11 | + replica_1_a = { |
| 12 | + master = true, |
| 13 | + }, |
| 14 | + replica_1_b = {}, |
| 15 | + }, |
| 16 | + }, |
| 17 | + { |
| 18 | + replicas = { |
| 19 | + replica_2_a = { |
| 20 | + master = true, |
| 21 | + }, |
| 22 | + replica_2_b = {}, |
| 23 | + }, |
| 24 | + }, |
| 25 | + }, |
| 26 | + bucket_count = 100, |
| 27 | +} |
| 28 | +local global_cfg = vtest.config_new(cfg_template) |
| 29 | + |
| 30 | +g.before_all(function() |
| 31 | + t.run_only_if(vutil.feature.ssl) |
| 32 | + vtest.cluster_new(g, global_cfg) |
| 33 | + vtest.cluster_bootstrap(g, global_cfg) |
| 34 | + vtest.cluster_rebalancer_disable(g) |
| 35 | + |
| 36 | + local new_cfg_template = table.deepcopy(cfg_template) |
| 37 | + new_cfg_template.sharding[1].is_ssl = true |
| 38 | + local new_global_cfg = vtest.config_new(new_cfg_template) |
| 39 | + |
| 40 | + g.router = vtest.router_new(g, 'router', new_global_cfg) |
| 41 | + vtest.cluster_cfg(g, new_global_cfg) |
| 42 | + vtest.router_cfg(g.router, new_global_cfg) |
| 43 | + |
| 44 | + local cert_dir = fio.pathjoin(fio.cwd(), './test/certs') |
| 45 | + g.sensitive_ssl_data = { |
| 46 | + ssl_cert_file = fio.pathjoin(cert_dir, 'server.crt'), |
| 47 | + ssl_key_file = fio.pathjoin(cert_dir, 'server.key'), |
| 48 | + ssl_ca_file = fio.pathjoin(cert_dir, 'ca.crt'), |
| 49 | + ssl_password = 'P4ssw0rd', |
| 50 | + ssl_password_file = 'PATH_TO_PASSWORD_FILE', |
| 51 | + ssl_ciphers = {'TLS_AES_256_GCM_SHA384', 'TLS_RSA_POLY1305_SHA256'} |
| 52 | + } |
| 53 | + vtest.cluster_wait_fullsync(g) |
| 54 | +end) |
| 55 | + |
| 56 | +g.after_all(function() |
| 57 | + g.cluster:drop() |
| 58 | +end) |
| 59 | + |
| 60 | +local function callrw_get_uuid(bid, timeout) |
| 61 | + timeout = timeout ~= nil and timeout or iwait_timeout |
| 62 | + return ivshard.router.callrw(bid, 'get_uuid', {}, {timeout = timeout}) |
| 63 | +end |
| 64 | + |
| 65 | +local function assert_no_sensitive_data_in_server_logs(server, sensitive_data) |
| 66 | + assert(type(sensitive_data) == 'table') |
| 67 | + for sensitive_key, sensitive_value in pairs(sensitive_data) do |
| 68 | + t.assert_not(server:grep_log(sensitive_key)) |
| 69 | + if type(sensitive_value) == 'table' then |
| 70 | + for _, sub_value in pairs(sensitive_value) do |
| 71 | + t.assert_not(server:grep_log(sub_value)) |
| 72 | + end |
| 73 | + else |
| 74 | + t.assert_not(server:grep_log(sensitive_value)) |
| 75 | + end |
| 76 | + end |
| 77 | +end |
| 78 | + |
| 79 | +g.test_no_ssl_sensitive_data_in_storage_logs = function(g) |
| 80 | + assert_no_sensitive_data_in_server_logs(g.replica_1_a, |
| 81 | + g.sensitive_ssl_data) |
| 82 | +end |
| 83 | + |
| 84 | +g.test_no_ssl_sensitive_data_in_router_logs = function(g) |
| 85 | + local replica_1_a_uri = g.router:exec(function(replicaset_id, master_uuid) |
| 86 | + local replicasets = ivshard.router.internal.static_router.replicasets |
| 87 | + local replica_1_a = replicasets[replicaset_id].replicas[master_uuid] |
| 88 | + return replica_1_a:safe_uri() |
| 89 | + end, {g.replica_1_a:replicaset_uuid(), g.replica_1_a:instance_uuid()}) |
| 90 | + |
| 91 | + t.assert_not(string.match(replica_1_a_uri, 'password')) |
| 92 | + for sensitive_key, _ in pairs(g.sensitive_ssl_data) do |
| 93 | + t.assert_not(string.match(replica_1_a_uri, sensitive_key)) |
| 94 | + end |
| 95 | + assert_no_sensitive_data_in_server_logs(g.router, g.sensitive_ssl_data) |
| 96 | +end |
| 97 | + |
| 98 | +g.test_ssl = function(g) |
| 99 | + t.run_only_if(vutil.feature.ssl) |
| 100 | + |
| 101 | + -- So as not to assume where buckets are located, find first bucket of the |
| 102 | + -- first replicaset. |
| 103 | + local bid1 = vtest.storage_first_bucket(g.replica_1_a) |
| 104 | + local bid2 = vtest.storage_first_bucket(g.replica_2_a) |
| 105 | + |
| 106 | + -- Enable SSL everywhere. |
| 107 | + local new_cfg_template = table.deepcopy(cfg_template) |
| 108 | + local sharding_templ = new_cfg_template.sharding |
| 109 | + local rs_1_templ = sharding_templ[1] |
| 110 | + local rs_2_templ = sharding_templ[2] |
| 111 | + rs_1_templ.is_ssl = true |
| 112 | + rs_2_templ.is_ssl = true |
| 113 | + |
| 114 | + local new_global_cfg = vtest.config_new(new_cfg_template) |
| 115 | + vtest.cluster_cfg(g, new_global_cfg) |
| 116 | + vtest.router_cfg(g.router, new_global_cfg) |
| 117 | + |
| 118 | + local rep_1_a_uuid = g.replica_1_a:instance_uuid() |
| 119 | + local res, err = g.router:exec(callrw_get_uuid, {bid1}) |
| 120 | + t.assert_equals(err, nil) |
| 121 | + t.assert_equals(res, rep_1_a_uuid, 'went to 1_a') |
| 122 | + |
| 123 | + local rep_2_a_uuid = g.replica_2_a:instance_uuid() |
| 124 | + res, err = g.router:exec(callrw_get_uuid, {bid2}) |
| 125 | + t.assert_equals(err, nil) |
| 126 | + t.assert_equals(res, rep_2_a_uuid, 'went to 2_a') |
| 127 | + |
| 128 | + -- Ensure that non-encrypted connection won't work. |
| 129 | + rs_2_templ.is_ssl = nil |
| 130 | + new_global_cfg = vtest.config_new(new_cfg_template) |
| 131 | + vtest.router_cfg(g.router, new_global_cfg) |
| 132 | + |
| 133 | + res, err = g.router:exec(callrw_get_uuid, {bid2, 0.01}) |
| 134 | + t.assert_equals(res, nil, 'rw failed on non-encrypted connection') |
| 135 | + t.assert_covers(err, {code = box.error.NO_CONNECTION}, 'got error') |
| 136 | + |
| 137 | + -- Works again when the replicaset also disables SSL. |
| 138 | + vtest.cluster_cfg(g, new_global_cfg) |
| 139 | + |
| 140 | + -- Force a reconnect right now instead of waiting until it happens |
| 141 | + -- automatically. |
| 142 | + vtest.router_disconnect(g.router) |
| 143 | + res, err = g.router:exec(callrw_get_uuid, {bid2}) |
| 144 | + t.assert_equals(err, nil, 'no error') |
| 145 | + t.assert_equals(res, rep_2_a_uuid, 'went to 2_a') |
| 146 | + |
| 147 | + -- Restore everything back. |
| 148 | + vtest.cluster_cfg(g, global_cfg) |
| 149 | + vtest.router_cfg(g.router, global_cfg) |
| 150 | + vtest.cluster_wait_fullsync(g) |
| 151 | +end |
0 commit comments