mirror of
https://github.com/pgsty/minio.git
synced 2026-08-09 15:53:28 +03:00
6613c2a3cb
The test and verification scripts invoked ./minio and pulled their tooling from upstream infrastructure with no integrity check. Every `curl | tar` of a client or an old server binary was an unverified execution path in a script that regularly runs as a privileged user, and several fetched a floating "latest". Two installers replace all of it: - install-mcli.sh resolves a pinned pgsty/mc release, downloads the archive and its checksum manifest, requires exactly one valid manifest entry for the asset, verifies it, and installs. MCLI_BIN with a mandatory MCLI_SHA256 lets an offline or air-gapped run supply its own binary, still checksum-checked. - install-verified-fixture.sh takes source, expected SHA-256 and target, and refuses anything that does not match. Sources may be a URL or a local file. Every script that previously downloaded mc now calls install-mcli.sh. The three places that genuinely need an upstream artifact - the old MinIO server binary for the LDAP IAM upgrade-import test, the 2021 mc for the three-site replication test, and the functional-tests.sh fixture - go through install-verified-fixture.sh with the digest recorded inline. Those dl.min.io URLs remain on purpose: they are historical upstream artifacts needed to prove upgrade compatibility, and they are now pinned and verified rather than trusted. The scripts otherwise switch to ./silo, silo.service, the silo container and compose service names, and SILO_CONFIG_DIR. run-multi-site-minio-idp.sh is renamed to run-multi-site-silo-idp.sh with the Makefile target following. buildscripts/minio-upgrade.sh keeps its name and its `minio server` argv - it exists to test the MinIO-to-Silo upgrade, so the old side must stay old - but it is now pinned to an image digest rather than a tag, and its `docker system prune` and `docker volume prune` calls are removed. Those ran unfiltered against the developer's whole Docker installation; the resiliency tests had the same problem and lose their prune and `docker ps -q` sweeps too. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
128 lines
3.7 KiB
Bash
Executable File
128 lines
3.7 KiB
Bash
Executable File
#!/bin/bash
|
|
|
|
# This script tests IAM migration from an old MinIO compatibility fixture into
|
|
# the current Silo server.
|
|
#
|
|
# To run it locally, start the LDAP server in github.com/minio/minio-iam-testing
|
|
# repo (e.g. make podman-run), and then run this script.
|
|
#
|
|
# This script assumes that LDAP server is at:
|
|
#
|
|
# `localhost:389`
|
|
#
|
|
# if this is not the case, set the environment variable
|
|
# `_MINIO_LDAP_TEST_SERVER`.
|
|
|
|
OLD_VERSION=RELEASE.2024-03-26T22-10-45Z
|
|
OLD_BINARY_LINK=https://dl.min.io/server/minio/release/linux-amd64/archive/minio.${OLD_VERSION}
|
|
OLD_BINARY_SHA256=2050199d89e3057571620a1d453118fed5bd2de9d4f3b266b11365fdf984d676
|
|
|
|
__init__() {
|
|
if which curl &>/dev/null; then
|
|
echo "curl is already installed"
|
|
else
|
|
echo "Installing curl:"
|
|
sudo apt install curl -y
|
|
fi
|
|
|
|
export GOPATH=/tmp/gopath
|
|
export PATH="${PATH}":"${GOPATH}"/bin
|
|
|
|
if [ ! -x "${GOPATH}/bin/mc" ]; then
|
|
echo "Installing verified compatible client fixture"
|
|
mkdir -p "${GOPATH}/bin"
|
|
"$(git rev-parse --show-toplevel)/buildscripts/install-mcli.sh" "${GOPATH}/bin/mc"
|
|
fi
|
|
|
|
if [ ! -x ./minio.${OLD_VERSION} ]; then
|
|
echo "Installing verified upstream compatibility fixture minio.${OLD_VERSION}"
|
|
"$(git rev-parse --show-toplevel)/buildscripts/install-verified-fixture.sh" \
|
|
"${OLD_BINARY_LINK}" "${OLD_BINARY_SHA256}" "minio.${OLD_VERSION}"
|
|
fi
|
|
|
|
if [ -z "$_MINIO_LDAP_TEST_SERVER" ]; then
|
|
export _MINIO_LDAP_TEST_SERVER=localhost:389
|
|
echo "Using default LDAP endpoint: $_MINIO_LDAP_TEST_SERVER"
|
|
fi
|
|
|
|
rm -rf /tmp/data
|
|
}
|
|
|
|
create_iam_content_in_old_minio() {
|
|
echo "Creating IAM content in the old MinIO compatibility fixture."
|
|
|
|
MINIO_CI_CD=1 ./minio.${OLD_VERSION} server /tmp/data/{1...4} &
|
|
sleep 5
|
|
|
|
set -x
|
|
mc alias set old-minio http://localhost:9000 minioadmin minioadmin
|
|
mc ready old-minio
|
|
mc idp ldap add old-minio \
|
|
server_addr=localhost:389 \
|
|
server_insecure=on \
|
|
lookup_bind_dn=cn=admin,dc=min,dc=io \
|
|
lookup_bind_password=admin \
|
|
user_dn_search_base_dn=dc=min,dc=io \
|
|
user_dn_search_filter="(uid=%s)" \
|
|
group_search_base_dn=ou=swengg,dc=min,dc=io \
|
|
group_search_filter="(&(objectclass=groupOfNames)(member=%d))"
|
|
mc admin service restart old-minio
|
|
|
|
mc idp ldap policy attach old-minio readwrite --user=UID=dillon,ou=people,ou=swengg,dc=min,dc=io
|
|
mc idp ldap policy attach old-minio readwrite --group=CN=project.c,ou=groups,ou=swengg,dc=min,dc=io
|
|
|
|
mc idp ldap policy entities old-minio
|
|
|
|
mc admin cluster iam export old-minio
|
|
set +x
|
|
|
|
mc admin service stop old-minio
|
|
}
|
|
|
|
import_iam_content_in_new_minio() {
|
|
echo "Importing IAM content into the current Silo instance."
|
|
# Assume the current Silo binary exists.
|
|
MINIO_CI_CD=1 ./silo server /tmp/data/{1...4} &
|
|
sleep 5
|
|
|
|
set -x
|
|
mc alias set new-minio http://localhost:9000 minioadmin minioadmin
|
|
echo "BEFORE IMPORT mappings:"
|
|
mc ready new-minio
|
|
mc idp ldap policy entities new-minio
|
|
mc admin cluster iam import new-minio ./old-minio-iam-info.zip
|
|
echo "AFTER IMPORT mappings:"
|
|
mc idp ldap policy entities new-minio
|
|
set +x
|
|
|
|
# mc admin service stop new-minio
|
|
}
|
|
|
|
verify_iam_content_in_new_minio() {
|
|
output=$(mc idp ldap policy entities new-minio --json)
|
|
|
|
groups=$(echo "$output" | jq -r '.result.policyMappings[] | select(.policy == "readwrite") | .groups[]')
|
|
if [ "$groups" != "cn=project.c,ou=groups,ou=swengg,dc=min,dc=io" ]; then
|
|
echo "Failed to verify groups: $groups"
|
|
exit 1
|
|
fi
|
|
|
|
users=$(echo "$output" | jq -r '.result.policyMappings[] | select(.policy == "readwrite") | .users[]')
|
|
if [ "$users" != "uid=dillon,ou=people,ou=swengg,dc=min,dc=io" ]; then
|
|
echo "Failed to verify users: $users"
|
|
exit 1
|
|
fi
|
|
|
|
mc admin service stop new-minio
|
|
}
|
|
|
|
main() {
|
|
create_iam_content_in_old_minio
|
|
|
|
import_iam_content_in_new_minio
|
|
|
|
verify_iam_content_in_new_minio
|
|
}
|
|
|
|
(__init__ "$@" && main "$@")
|