]>
git.proxmox.com Git - ceph.git/blob - ceph/qa/tasks/cephfs/test_pool_perm.py
1 from textwrap
import dedent
2 from teuthology
.exceptions
import CommandFailedError
3 from tasks
.cephfs
.cephfs_test_case
import CephFSTestCase
7 class TestPoolPerm(CephFSTestCase
):
8 def test_pool_perm(self
):
9 self
.mount_a
.run_shell(["touch", "test_file"])
11 file_path
= os
.path
.join(self
.mount_a
.mountpoint
, "test_file")
13 remote_script
= dedent("""
17 fd = os.open("{path}", os.O_RDWR)
20 ret = os.read(fd, 1024)
22 os.write(fd, b'content')
24 if e.errno != errno.EPERM:
27 raise RuntimeError("client does not check permission of data pool")
30 client_name
= "client.{0}".format(self
.mount_a
.client_id
)
32 # set data pool read only
33 self
.fs
.mon_manager
.raw_cluster_cmd_result(
34 'auth', 'caps', client_name
, 'mds', 'allow', 'mon', 'allow r', 'osd',
35 'allow r pool={0}'.format(self
.fs
.get_data_pool_name()))
37 self
.mount_a
.umount_wait()
38 self
.mount_a
.mount_wait()
41 self
.mount_a
.run_python(remote_script
.format(path
=file_path
, check_read
=str(False)))
43 # set data pool write only
44 self
.fs
.mon_manager
.raw_cluster_cmd_result(
45 'auth', 'caps', client_name
, 'mds', 'allow', 'mon', 'allow r', 'osd',
46 'allow w pool={0}'.format(self
.fs
.get_data_pool_name()))
48 self
.mount_a
.umount_wait()
49 self
.mount_a
.mount_wait()
52 self
.mount_a
.run_python(remote_script
.format(path
=file_path
, check_read
=str(True)))
54 def test_forbidden_modification(self
):
56 That a client who does not have the capability for setting
57 layout pools is prevented from doing so.
61 client_name
= "client.{0}".format(self
.mount_a
.client_id
)
62 new_pool_name
= "data_new"
63 self
.fs
.add_data_pool(new_pool_name
)
65 self
.mount_a
.run_shell(["touch", "layoutfile"])
66 self
.mount_a
.run_shell(["mkdir", "layoutdir"])
68 # Set MDS 'rw' perms: missing 'p' means no setting pool layouts
69 self
.fs
.mon_manager
.raw_cluster_cmd_result(
70 'auth', 'caps', client_name
, 'mds', 'allow rw', 'mon', 'allow r',
72 'allow rw pool={0},allow rw pool={1}'.format(
73 self
.fs
.get_data_pool_names()[0],
74 self
.fs
.get_data_pool_names()[1],
77 self
.mount_a
.umount_wait()
78 self
.mount_a
.mount_wait()
80 with self
.assertRaises(CommandFailedError
):
81 self
.mount_a
.setfattr("layoutfile", "ceph.file.layout.pool",
83 with self
.assertRaises(CommandFailedError
):
84 self
.mount_a
.setfattr("layoutdir", "ceph.dir.layout.pool",
86 self
.mount_a
.umount_wait()
88 # Set MDS 'rwp' perms: should now be able to set layouts
89 self
.fs
.mon_manager
.raw_cluster_cmd_result(
90 'auth', 'caps', client_name
, 'mds', 'allow rwp', 'mon', 'allow r',
92 'allow rw pool={0},allow rw pool={1}'.format(
93 self
.fs
.get_data_pool_names()[0],
94 self
.fs
.get_data_pool_names()[1],
96 self
.mount_a
.mount_wait()
97 self
.mount_a
.setfattr("layoutfile", "ceph.file.layout.pool",
99 self
.mount_a
.setfattr("layoutdir", "ceph.dir.layout.pool",
101 self
.mount_a
.umount_wait()
104 self
.fs
.mon_manager
.raw_cluster_cmd_result(
105 'auth', 'caps', "client.{0}".format(self
.mount_a
.client_id
),
106 'mds', 'allow', 'mon', 'allow r', 'osd',
107 'allow rw pool={0}'.format(self
.fs
.get_data_pool_names()[0]))
108 super(TestPoolPerm
, self
).tearDown()