accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
/*
|
|
|
|
* Minio Cloud Storage, (C) 2015, 2016 Minio, Inc.
|
|
|
|
*
|
|
|
|
* Licensed under the Apache License, Version 2.0 (the "License");
|
|
|
|
* you may not use this file except in compliance with the License.
|
|
|
|
* You may obtain a copy of the License at
|
|
|
|
*
|
|
|
|
* http://www.apache.org/licenses/LICENSE-2.0
|
|
|
|
*
|
|
|
|
* Unless required by applicable law or agreed to in writing, software
|
|
|
|
* distributed under the License is distributed on an "AS IS" BASIS,
|
|
|
|
* WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
|
|
* See the License for the specific language governing permissions and
|
|
|
|
* limitations under the License.
|
|
|
|
*/
|
|
|
|
|
2016-08-18 16:23:42 -07:00
|
|
|
package cmd
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
|
|
|
|
import (
|
2016-07-28 20:49:08 -07:00
|
|
|
"bytes"
|
2016-10-13 09:19:04 -07:00
|
|
|
"encoding/json"
|
2016-08-10 20:10:48 -07:00
|
|
|
"io"
|
2016-09-26 14:28:35 -07:00
|
|
|
"sync"
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
)
|
|
|
|
|
2017-01-10 16:43:48 -08:00
|
|
|
const (
|
|
|
|
// Static prefix to be used while constructing bucket ARN.
|
|
|
|
// refer to S3 docs for more info.
|
|
|
|
bucketARNPrefix = "arn:" + eventSource + ":::"
|
2017-01-16 17:05:00 -08:00
|
|
|
|
|
|
|
// Bucket policy config name.
|
|
|
|
bucketPolicyConfig = "policy.json"
|
2017-01-10 16:43:48 -08:00
|
|
|
)
|
|
|
|
|
2016-09-26 14:28:35 -07:00
|
|
|
// Variable represents bucket policies in memory.
|
|
|
|
var globalBucketPolicies *bucketPolicies
|
|
|
|
|
|
|
|
// Global bucket policies list, policies are enforced on each bucket looking
|
|
|
|
// through the policies here.
|
|
|
|
type bucketPolicies struct {
|
|
|
|
rwMutex *sync.RWMutex
|
|
|
|
|
|
|
|
// Collection of 'bucket' policies.
|
|
|
|
bucketPolicyConfigs map[string]*bucketPolicy
|
|
|
|
}
|
|
|
|
|
2016-10-13 09:19:04 -07:00
|
|
|
// Represent a policy change
|
|
|
|
type policyChange struct {
|
|
|
|
// isRemove is true if the policy change is to delete the
|
|
|
|
// policy on a bucket.
|
|
|
|
IsRemove bool
|
|
|
|
|
|
|
|
// represents the new policy for the bucket
|
|
|
|
BktPolicy *bucketPolicy
|
|
|
|
}
|
|
|
|
|
2016-09-26 14:28:35 -07:00
|
|
|
// Fetch bucket policy for a given bucket.
|
|
|
|
func (bp bucketPolicies) GetBucketPolicy(bucket string) *bucketPolicy {
|
|
|
|
bp.rwMutex.RLock()
|
|
|
|
defer bp.rwMutex.RUnlock()
|
|
|
|
return bp.bucketPolicyConfigs[bucket]
|
|
|
|
}
|
|
|
|
|
|
|
|
// Set a new bucket policy for a bucket, this operation will overwrite
|
2016-10-13 09:19:04 -07:00
|
|
|
// any previous bucket policies for the bucket.
|
|
|
|
func (bp *bucketPolicies) SetBucketPolicy(bucket string, pCh policyChange) error {
|
2016-09-26 14:28:35 -07:00
|
|
|
bp.rwMutex.Lock()
|
|
|
|
defer bp.rwMutex.Unlock()
|
2016-10-13 09:19:04 -07:00
|
|
|
|
|
|
|
if pCh.IsRemove {
|
|
|
|
delete(bp.bucketPolicyConfigs, bucket)
|
|
|
|
} else {
|
|
|
|
if pCh.BktPolicy == nil {
|
|
|
|
return errInvalidArgument
|
|
|
|
}
|
|
|
|
bp.bucketPolicyConfigs[bucket] = pCh.BktPolicy
|
2016-09-26 14:28:35 -07:00
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Loads all bucket policies from persistent layer.
|
|
|
|
func loadAllBucketPolicies(objAPI ObjectLayer) (policies map[string]*bucketPolicy, err error) {
|
|
|
|
// List buckets to proceed loading all notification configuration.
|
|
|
|
buckets, err := objAPI.ListBuckets()
|
|
|
|
errorIf(err, "Unable to list buckets.")
|
|
|
|
if err != nil {
|
2016-11-19 17:37:57 -08:00
|
|
|
return nil, errorCause(err)
|
2016-09-26 14:28:35 -07:00
|
|
|
}
|
|
|
|
|
|
|
|
policies = make(map[string]*bucketPolicy)
|
|
|
|
var pErrs []error
|
|
|
|
// Loads bucket policy.
|
|
|
|
for _, bucket := range buckets {
|
|
|
|
policy, pErr := readBucketPolicy(bucket.Name, objAPI)
|
|
|
|
if pErr != nil {
|
2016-11-23 20:05:04 -08:00
|
|
|
// net.Dial fails for rpc client or any
|
|
|
|
// other unexpected errors during net.Dial.
|
|
|
|
if !isErrIgnored(pErr, errDiskNotFound) {
|
2016-11-19 17:37:57 -08:00
|
|
|
if !isErrBucketPolicyNotFound(pErr) {
|
|
|
|
pErrs = append(pErrs, pErr)
|
|
|
|
}
|
2016-09-26 14:28:35 -07:00
|
|
|
}
|
|
|
|
// Continue to load other bucket policies if possible.
|
|
|
|
continue
|
|
|
|
}
|
|
|
|
policies[bucket.Name] = policy
|
|
|
|
}
|
|
|
|
|
|
|
|
// Look for any errors occurred while reading bucket policies.
|
|
|
|
for _, pErr := range pErrs {
|
|
|
|
if pErr != nil {
|
|
|
|
return policies, pErr
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Success.
|
|
|
|
return policies, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// Intialize all bucket policies.
|
|
|
|
func initBucketPolicies(objAPI ObjectLayer) error {
|
|
|
|
if objAPI == nil {
|
|
|
|
return errInvalidArgument
|
|
|
|
}
|
|
|
|
|
|
|
|
// Read all bucket policies.
|
|
|
|
policies, err := loadAllBucketPolicies(objAPI)
|
|
|
|
if err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
|
|
|
|
// Populate global bucket collection.
|
|
|
|
globalBucketPolicies = &bucketPolicies{
|
|
|
|
rwMutex: &sync.RWMutex{},
|
|
|
|
bucketPolicyConfigs: policies,
|
|
|
|
}
|
|
|
|
|
|
|
|
// Success.
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2016-08-30 22:34:50 +05:30
|
|
|
// readBucketPolicyJSON - reads bucket policy for an input bucket, returns BucketPolicyNotFound
|
|
|
|
// if bucket policy is not found.
|
|
|
|
func readBucketPolicyJSON(bucket string, objAPI ObjectLayer) (bucketPolicyReader io.Reader, err error) {
|
2017-01-16 17:05:00 -08:00
|
|
|
policyPath := pathJoin(bucketConfigPrefix, bucket, bucketPolicyConfig)
|
2016-12-10 16:15:12 -08:00
|
|
|
|
|
|
|
// Acquire a read lock on policy config before reading.
|
|
|
|
objLock := globalNSMutex.NewNSLock(minioMetaBucket, policyPath)
|
2017-08-31 11:29:22 -07:00
|
|
|
if err = objLock.GetRLock(globalOperationTimeout); err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
2016-12-10 16:15:12 -08:00
|
|
|
defer objLock.RUnlock()
|
|
|
|
|
2016-07-28 20:49:08 -07:00
|
|
|
var buffer bytes.Buffer
|
2016-12-21 11:29:32 -08:00
|
|
|
err = objAPI.GetObject(minioMetaBucket, policyPath, 0, -1, &buffer)
|
2016-07-28 20:49:08 -07:00
|
|
|
if err != nil {
|
2016-11-19 17:37:57 -08:00
|
|
|
if isErrObjectNotFound(err) || isErrIncompleteBody(err) {
|
2016-04-29 14:24:10 -07:00
|
|
|
return nil, BucketPolicyNotFound{Bucket: bucket}
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
2016-09-06 13:30:05 -07:00
|
|
|
errorIf(err, "Unable to load policy for the bucket %s.", bucket)
|
2016-11-19 17:37:57 -08:00
|
|
|
return nil, errorCause(err)
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
2016-08-30 22:34:50 +05:30
|
|
|
|
|
|
|
return &buffer, nil
|
|
|
|
}
|
|
|
|
|
|
|
|
// readBucketPolicy - reads bucket policy for an input bucket, returns BucketPolicyNotFound
|
|
|
|
// if bucket policy is not found. This function also parses the bucket policy into an object.
|
|
|
|
func readBucketPolicy(bucket string, objAPI ObjectLayer) (*bucketPolicy, error) {
|
|
|
|
// Read bucket policy JSON.
|
|
|
|
bucketPolicyReader, err := readBucketPolicyJSON(bucket, objAPI)
|
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
}
|
|
|
|
|
2016-08-10 20:10:48 -07:00
|
|
|
// Parse the saved policy.
|
|
|
|
var policy = &bucketPolicy{}
|
2016-08-30 22:34:50 +05:30
|
|
|
err = parseBucketPolicy(bucketPolicyReader, policy)
|
2016-08-10 20:10:48 -07:00
|
|
|
if err != nil {
|
|
|
|
return nil, err
|
|
|
|
|
|
|
|
}
|
|
|
|
return policy, nil
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
|
|
|
|
2016-08-10 20:10:48 -07:00
|
|
|
// removeBucketPolicy - removes any previously written bucket policy. Returns BucketPolicyNotFound
|
|
|
|
// if no policies are found.
|
2016-08-09 11:33:45 -07:00
|
|
|
func removeBucketPolicy(bucket string, objAPI ObjectLayer) error {
|
2017-01-16 17:05:00 -08:00
|
|
|
policyPath := pathJoin(bucketConfigPrefix, bucket, bucketPolicyConfig)
|
2016-12-10 16:15:12 -08:00
|
|
|
// Acquire a write lock on policy config before modifying.
|
|
|
|
objLock := globalNSMutex.NewNSLock(minioMetaBucket, policyPath)
|
2017-08-31 11:29:22 -07:00
|
|
|
if err := objLock.GetLock(globalOperationTimeout); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2016-12-10 16:15:12 -08:00
|
|
|
defer objLock.Unlock()
|
2016-08-09 11:33:45 -07:00
|
|
|
if err := objAPI.DeleteObject(minioMetaBucket, policyPath); err != nil {
|
2016-08-25 22:09:01 +05:30
|
|
|
errorIf(err, "Unable to remove bucket-policy on bucket %s.", bucket)
|
|
|
|
err = errorCause(err)
|
2016-07-28 20:49:08 -07:00
|
|
|
if _, ok := err.(ObjectNotFound); ok {
|
2016-04-29 14:24:10 -07:00
|
|
|
return BucketPolicyNotFound{Bucket: bucket}
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
2016-04-29 14:24:10 -07:00
|
|
|
return err
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
|
|
|
return nil
|
|
|
|
}
|
|
|
|
|
2016-11-19 17:37:57 -08:00
|
|
|
// writeBucketPolicy - save a bucket policy that is assumed to be validated.
|
2016-10-13 09:19:04 -07:00
|
|
|
func writeBucketPolicy(bucket string, objAPI ObjectLayer, bpy *bucketPolicy) error {
|
|
|
|
buf, err := json.Marshal(bpy)
|
|
|
|
if err != nil {
|
|
|
|
errorIf(err, "Unable to marshal bucket policy '%v' to JSON", *bpy)
|
|
|
|
return err
|
|
|
|
}
|
2017-01-16 17:05:00 -08:00
|
|
|
policyPath := pathJoin(bucketConfigPrefix, bucket, bucketPolicyConfig)
|
2016-12-10 16:15:12 -08:00
|
|
|
// Acquire a write lock on policy config before modifying.
|
|
|
|
objLock := globalNSMutex.NewNSLock(minioMetaBucket, policyPath)
|
2017-08-31 11:29:22 -07:00
|
|
|
if err := objLock.GetLock(globalOperationTimeout); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
2016-12-10 16:15:12 -08:00
|
|
|
defer objLock.Unlock()
|
2017-09-19 12:40:27 -07:00
|
|
|
if _, err := objAPI.PutObject(minioMetaBucket, policyPath, NewHashReader(bytes.NewReader(buf), int64(len(buf)), "", ""), nil); err != nil {
|
2016-08-25 22:09:01 +05:30
|
|
|
errorIf(err, "Unable to set policy for the bucket %s", bucket)
|
|
|
|
return errorCause(err)
|
|
|
|
}
|
|
|
|
return nil
|
accessPolicy: Implement Put, Get, Delete access policy.
This patch implements Get,Put,Delete bucket policies
Supporting - http://docs.aws.amazon.com/AmazonS3/latest/dev/access-policy-language-overview.html
Currently supports following actions.
"*": true,
"s3:*": true,
"s3:GetObject": true,
"s3:ListBucket": true,
"s3:PutObject": true,
"s3:CreateBucket": true,
"s3:GetBucketLocation": true,
"s3:DeleteBucket": true,
"s3:DeleteObject": true,
"s3:AbortMultipartUpload": true,
"s3:ListBucketMultipartUploads": true,
"s3:ListMultipartUploadParts": true,
following conditions for "StringEquals" and "StringNotEquals"
"s3:prefix", "s3:max-keys"
2016-02-03 16:46:56 -08:00
|
|
|
}
|
2016-12-10 16:15:12 -08:00
|
|
|
|
|
|
|
func parseAndPersistBucketPolicy(bucket string, policyBytes []byte, objAPI ObjectLayer) APIErrorCode {
|
|
|
|
// Parse bucket policy.
|
|
|
|
var policy = &bucketPolicy{}
|
|
|
|
err := parseBucketPolicy(bytes.NewReader(policyBytes), policy)
|
|
|
|
if err != nil {
|
|
|
|
errorIf(err, "Unable to parse bucket policy.")
|
|
|
|
return ErrInvalidPolicyDocument
|
|
|
|
}
|
|
|
|
|
|
|
|
// Parse check bucket policy.
|
|
|
|
if s3Error := checkBucketPolicyResources(bucket, policy); s3Error != ErrNone {
|
|
|
|
return s3Error
|
|
|
|
}
|
|
|
|
|
|
|
|
// Acquire a write lock on bucket before modifying its configuration.
|
|
|
|
bucketLock := globalNSMutex.NewNSLock(bucket, "")
|
2017-08-31 11:29:22 -07:00
|
|
|
if bucketLock.GetLock(globalOperationTimeout) != nil {
|
|
|
|
return ErrOperationTimedOut
|
|
|
|
}
|
2016-12-10 16:15:12 -08:00
|
|
|
// Release lock after notifying peers
|
|
|
|
defer bucketLock.Unlock()
|
|
|
|
|
|
|
|
// Save bucket policy.
|
|
|
|
if err = persistAndNotifyBucketPolicyChange(bucket, policyChange{false, policy}, objAPI); err != nil {
|
|
|
|
switch err.(type) {
|
|
|
|
case BucketNameInvalid:
|
|
|
|
return ErrInvalidBucketName
|
|
|
|
case BucketNotFound:
|
|
|
|
return ErrNoSuchBucket
|
|
|
|
default:
|
|
|
|
errorIf(err, "Unable to save bucket policy.")
|
|
|
|
return ErrInternalError
|
|
|
|
}
|
|
|
|
}
|
|
|
|
return ErrNone
|
|
|
|
}
|
|
|
|
|
|
|
|
// persistAndNotifyBucketPolicyChange - takes a policyChange argument,
|
|
|
|
// persists it to storage, and notify nodes in the cluster about the
|
|
|
|
// change. In-memory state is updated in response to the notification.
|
|
|
|
func persistAndNotifyBucketPolicyChange(bucket string, pCh policyChange, objAPI ObjectLayer) error {
|
|
|
|
if pCh.IsRemove {
|
|
|
|
if err := removeBucketPolicy(bucket, objAPI); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
} else {
|
|
|
|
if pCh.BktPolicy == nil {
|
|
|
|
return errInvalidArgument
|
|
|
|
}
|
|
|
|
if err := writeBucketPolicy(bucket, objAPI, pCh.BktPolicy); err != nil {
|
|
|
|
return err
|
|
|
|
}
|
|
|
|
}
|
|
|
|
|
|
|
|
// Notify all peers (including self) to update in-memory state
|
|
|
|
S3PeersUpdateBucketPolicy(bucket, pCh)
|
|
|
|
return nil
|
|
|
|
}
|