mirror of
https://github.com/rustfs/rustfs.git
synced 2026-09-01 09:48:20 +00:00
fix(ci): restore tier e2e and locked builds (#6773)
* fix(tier): restore loopback e2e coverage safely * fix(build): sync scanner dev dependency lock
This commit is contained in:
@@ -32,12 +32,32 @@ use rustfs_s3_client::{
|
||||
credentials::{Credentials, SignatureType, Static, Value},
|
||||
transition_api::{Options, ReadCloser, ReaderImpl, TransitionClient, TransitionCore},
|
||||
};
|
||||
use rustfs_utils::egress::validate_outbound_url;
|
||||
use rustfs_utils::egress::{OutboundUrlError, validate_outbound_url};
|
||||
|
||||
const MAX_MULTIPART_PUT_OBJECT_SIZE: i64 = 1024 * 1024 * 1024 * 1024 * 5;
|
||||
const MAX_PARTS_COUNT: i64 = 10000;
|
||||
const _MAX_PART_SIZE: i64 = 1024 * 1024 * 1024 * 5;
|
||||
const MIN_PART_SIZE: i64 = 1024 * 1024 * 128;
|
||||
// Debug-only opt-in for single-host test/dev setups; release builds always reject loopback.
|
||||
const ALLOW_LOOPBACK_TIER_ENDPOINT_ENV: &str = "RUSTFS_TIER_RUSTFS_ALLOW_LOOPBACK_ENDPOINT";
|
||||
|
||||
fn validate_rustfs_tier_endpoint(url: &url::Url) -> Result<(), OutboundUrlError> {
|
||||
let allow_loopback = cfg!(debug_assertions)
|
||||
&& std::env::var(ALLOW_LOOPBACK_TIER_ENDPOINT_ENV)
|
||||
.map(|value| value == "1" || value.eq_ignore_ascii_case("true"))
|
||||
.unwrap_or(false);
|
||||
validate_rustfs_tier_endpoint_inner(url, allow_loopback)
|
||||
}
|
||||
|
||||
fn validate_rustfs_tier_endpoint_inner(url: &url::Url, allow_loopback: bool) -> Result<(), OutboundUrlError> {
|
||||
match validate_outbound_url(url) {
|
||||
Err(OutboundUrlError::ForbiddenHost {
|
||||
reason: "loopback address" | "loopback host",
|
||||
..
|
||||
}) if allow_loopback => Ok(()),
|
||||
result => result,
|
||||
}
|
||||
}
|
||||
|
||||
pub struct WarmBackendRustFS(WarmBackendS3);
|
||||
|
||||
@@ -55,7 +75,7 @@ impl WarmBackendRustFS {
|
||||
Ok(u) => u,
|
||||
Err(e) => return Err(std::io::Error::other(e)),
|
||||
};
|
||||
validate_outbound_url(&u).map_err(|err| std::io::Error::other(format!("tier endpoint is not allowed: {err}")))?;
|
||||
validate_rustfs_tier_endpoint(&u).map_err(|err| std::io::Error::other(format!("tier endpoint is not allowed: {err}")))?;
|
||||
|
||||
let creds = Credentials::new(Static(Value {
|
||||
access_key_id: conf.access_key.clone(),
|
||||
@@ -208,4 +228,13 @@ mod tests {
|
||||
Err(err) => assert!(err.to_string().contains("not allowed")),
|
||||
}
|
||||
}
|
||||
|
||||
#[test]
|
||||
fn loopback_opt_in_does_not_allow_other_private_endpoints() {
|
||||
let loopback = url::Url::parse("https://127.0.0.1:9000").unwrap();
|
||||
assert!(validate_rustfs_tier_endpoint_inner(&loopback, true).is_ok());
|
||||
|
||||
let private = url::Url::parse("https://10.0.0.1:9000").unwrap();
|
||||
assert!(validate_rustfs_tier_endpoint_inner(&private, true).is_err());
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user