mirror of
https://github.com/rustfs/rustfs.git
synced 2026-07-27 08:38:58 +00:00
284 lines
11 KiB
Rust
284 lines
11 KiB
Rust
// Copyright 2024 RustFS Team
|
|
//
|
|
// Licensed under the Apache License, Version 2.0 (the "License");
|
|
// you may not use this file except in compliance with the License.
|
|
// You may obtain a copy of the License at
|
|
//
|
|
// http://www.apache.org/licenses/LICENSE-2.0
|
|
//
|
|
// Unless required by applicable law or agreed to in writing, software
|
|
// distributed under the License is distributed on an "AS IS" BASIS,
|
|
// WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
|
|
// See the License for the specific language governing permissions and
|
|
// limitations under the License.
|
|
|
|
use rustfs_security_governance::{RedactionLevel, RedactionPolicyError, RedactionRule, validate_redaction_rules};
|
|
pub use rustfs_utils::MaskedAccessKey;
|
|
|
|
pub const REDACTED_LOG_VALUE: &str = "***redacted***";
|
|
|
|
pub const LOGGING_REDACTION_RULES: &[RedactionRule] = &[
|
|
RedactionRule::new("access_key", RedactionLevel::Sensitive, "principal identifiers should be masked in logs"),
|
|
RedactionRule::new(
|
|
"authorization",
|
|
RedactionLevel::Secret,
|
|
"authorization headers may carry bearer or signature material",
|
|
),
|
|
RedactionRule::new(
|
|
"client_secret",
|
|
RedactionLevel::Secret,
|
|
"OIDC and external provider client secrets must never be logged",
|
|
),
|
|
RedactionRule::new("secret_key", RedactionLevel::Secret, "secret access keys must never be logged"),
|
|
RedactionRule::new(
|
|
"session_token",
|
|
RedactionLevel::Secret,
|
|
"session tokens can be replayed if exposed in logs",
|
|
),
|
|
RedactionRule::new("token", RedactionLevel::Secret, "generic token fields are treated as secret by default"),
|
|
];
|
|
|
|
pub fn validate_logging_redaction_rules() -> Result<(), RedactionPolicyError> {
|
|
validate_redaction_rules(LOGGING_REDACTION_RULES)
|
|
}
|
|
|
|
pub fn is_sensitive_log_field(field_name: &str) -> bool {
|
|
LOGGING_REDACTION_RULES
|
|
.iter()
|
|
.any(|rule| rule.field().eq_ignore_ascii_case(field_name.trim()) && rule.level().requires_redaction())
|
|
}
|
|
|
|
pub fn redacted_log_value(value: &str) -> &'static str {
|
|
if value.is_empty() { "" } else { REDACTED_LOG_VALUE }
|
|
}
|
|
|
|
pub fn redacted_optional_log_value(value: Option<&str>) -> Option<&'static str> {
|
|
value.map(redacted_log_value)
|
|
}
|
|
|
|
#[cfg(test)]
|
|
mod tests {
|
|
use super::*;
|
|
use std::fs;
|
|
use std::path::{Path, PathBuf};
|
|
|
|
fn workspace_root() -> PathBuf {
|
|
Path::new(env!("CARGO_MANIFEST_DIR"))
|
|
.parent()
|
|
.and_then(Path::parent)
|
|
.expect("workspace root should exist")
|
|
.to_path_buf()
|
|
}
|
|
|
|
fn assert_no_unmasked_access_key_logging(rel_path: &str, forbidden_patterns: &[&str]) {
|
|
let path = workspace_root().join(rel_path);
|
|
let source = fs::read_to_string(&path).unwrap_or_else(|err| panic!("failed to read {}: {}", path.display(), err));
|
|
for pattern in forbidden_patterns {
|
|
assert!(
|
|
!source.contains(pattern),
|
|
"found forbidden unmasked access_key logging pattern `{}` in {}",
|
|
pattern,
|
|
path.display()
|
|
);
|
|
}
|
|
}
|
|
|
|
fn assert_source_contains(rel_path: &str, required_patterns: &[&str]) {
|
|
let path = workspace_root().join(rel_path);
|
|
let source = fs::read_to_string(&path).unwrap_or_else(|err| panic!("failed to read {}: {}", path.display(), err));
|
|
for pattern in required_patterns {
|
|
assert!(
|
|
source.contains(pattern),
|
|
"missing required logging governance pattern `{}` in {}",
|
|
pattern,
|
|
path.display()
|
|
);
|
|
}
|
|
}
|
|
|
|
#[test]
|
|
fn logging_redaction_rules_are_valid() {
|
|
assert!(validate_logging_redaction_rules().is_ok());
|
|
}
|
|
|
|
#[test]
|
|
fn identifies_sensitive_log_fields_case_insensitively() {
|
|
assert!(is_sensitive_log_field("access_key"));
|
|
assert!(is_sensitive_log_field("Authorization"));
|
|
assert!(is_sensitive_log_field("session_token"));
|
|
assert!(!is_sensitive_log_field("bucket"));
|
|
assert!(!is_sensitive_log_field("status_code"));
|
|
}
|
|
|
|
#[test]
|
|
fn redacted_log_value_preserves_empty_values() {
|
|
assert_eq!(redacted_log_value(""), "");
|
|
assert_eq!(redacted_log_value("secret"), REDACTED_LOG_VALUE);
|
|
assert_eq!(redacted_optional_log_value(None), None);
|
|
assert_eq!(redacted_optional_log_value(Some("")), Some(""));
|
|
assert_eq!(redacted_optional_log_value(Some("secret")), Some(REDACTED_LOG_VALUE));
|
|
}
|
|
|
|
#[test]
|
|
fn masked_access_key_masks_short_values() {
|
|
assert_eq!(MaskedAccessKey("").to_string(), "");
|
|
assert_eq!(MaskedAccessKey("a").to_string(), "***");
|
|
assert_eq!(MaskedAccessKey("abcd").to_string(), "***");
|
|
assert_eq!(MaskedAccessKey("abcde").to_string(), "a***e");
|
|
assert_eq!(MaskedAccessKey("abcdefgh").to_string(), "a***h");
|
|
}
|
|
|
|
#[test]
|
|
fn masked_access_key_masks_long_values() {
|
|
assert_eq!(MaskedAccessKey("AKIAIOSFODNN7EXAMPLE").to_string(), "AKIA***MPLE");
|
|
assert_eq!(format!("{:?}", MaskedAccessKey("keystone:user-1234")), "keys***1234");
|
|
}
|
|
|
|
#[test]
|
|
fn runtime_auth_logging_does_not_use_previous_unmasked_access_key_patterns() {
|
|
assert_no_unmasked_access_key_logging(
|
|
"rustfs/src/auth.rs",
|
|
&[
|
|
"get_secret_key failed: no such user, access_key: {access_key}",
|
|
"get_secret_key failed: check_key error, access_key: {access_key}, error: {e:?}",
|
|
"get_secret_key failed: iam not initialized, access_key: {access_key}",
|
|
"check_key_valid: user not found for access_key={}",
|
|
"check_key_valid: account disabled for access_key={}",
|
|
"check_key_valid: validation failed for access_key={}",
|
|
"check_key_valid: starting validation - access_key={}, session_token_len={}",
|
|
],
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn protocol_client_logging_does_not_use_previous_unmasked_access_key_pattern() {
|
|
assert_no_unmasked_access_key_logging(
|
|
"rustfs/src/protocols/client.rs",
|
|
&["Protocol storage client ListBuckets request: access_key={}"],
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn startup_runtime_logging_does_not_dump_full_config_debug_output() {
|
|
let path = workspace_root().join("rustfs/src/main.rs");
|
|
let source = fs::read_to_string(&path).unwrap_or_else(|err| panic!("failed to read {}: {}", path.display(), err));
|
|
assert!(
|
|
!source.contains("debug!(\"config: {:?}\", &config)"),
|
|
"found forbidden full config debug output in {}",
|
|
path.display()
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn startup_fatal_stderr_uses_single_formatter_for_pre_observability_failures() {
|
|
assert_source_contains(
|
|
"rustfs/src/main.rs",
|
|
&[
|
|
"fn format_fatal_stderr_message(context: &str, error: impl std::fmt::Display) -> String",
|
|
"fn emit_fatal_stderr(context: &str, error: impl std::fmt::Display)",
|
|
"emit_fatal_stderr(\"Server runtime failed\", e)",
|
|
"emit_fatal_stderr(\"Command parse failed\", e)",
|
|
"emit_fatal_stderr(\"Observability initialization failed\", &e)",
|
|
],
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn observability_runtime_logging_uses_tracing_for_fallback_and_guard_shutdown() {
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/obs/src/telemetry/local.rs",
|
|
&[
|
|
"[WARN] Failed to initialize file observability logging",
|
|
"Falling back to stdout logging.",
|
|
],
|
|
);
|
|
assert_source_contains(
|
|
"crates/obs/src/telemetry/local.rs",
|
|
&[
|
|
"warn!(",
|
|
"state = \"fallback_to_stdout\"",
|
|
"failed_sink = \"file\"",
|
|
"sink = \"stdout\"",
|
|
],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/obs/src/telemetry/guard.rs",
|
|
&[
|
|
"eprintln!(\"Tracer shutdown error: {err:?}\")",
|
|
"eprintln!(\"Meter shutdown error: {err:?}\")",
|
|
"eprintln!(\"Logger shutdown error: {err:?}\")",
|
|
"eprintln!(\"Log cleanup task stopped\")",
|
|
"eprintln!(\"Tracing guard dropped, flushing logs.\")",
|
|
"eprintln!(\"Stdout guard dropped, flushing logs.\")",
|
|
],
|
|
);
|
|
assert_source_contains(
|
|
"crates/obs/src/telemetry/guard.rs",
|
|
&[
|
|
"EVENT_OBS_GUARD_SHUTDOWN",
|
|
"resource = \"tracer_provider\"",
|
|
"resource = \"meter_provider\"",
|
|
"resource = \"logger_provider\"",
|
|
"resource = \"log_cleaner\"",
|
|
"resource = \"tracing_guard\"",
|
|
"resource = \"stdout_guard\"",
|
|
],
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn low_level_logging_sink_stderr_exceptions_remain_explicit() {
|
|
assert_source_contains(
|
|
"crates/obs/src/telemetry/rolling.rs",
|
|
&[
|
|
"Failed to flush log file before rotation",
|
|
"RollingAppender: Failed to rotate log file after",
|
|
"RollingAppender: failed to rotate log file",
|
|
],
|
|
);
|
|
}
|
|
|
|
#[test]
|
|
fn audit_notify_runtime_logging_does_not_use_previous_sentence_first_noise_patterns() {
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/audit/src/pipeline.rs",
|
|
&[
|
|
"No audit targets configured for dispatch",
|
|
"No audit targets configured for batch dispatch",
|
|
"Successfully sent audit entry, target: {}, key: {}",
|
|
"Target {} not connected, retrying...",
|
|
"Timeout sending to target {}, retrying...",
|
|
],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/notify/src/runtime_facade.rs",
|
|
&[
|
|
"Event stream processing for target {} is started successfully",
|
|
"Target {} has no replay worker to start",
|
|
],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/notify/src/notifier.rs",
|
|
&[
|
|
"Sending event to targets: {:?}",
|
|
"Event processing initiated for {} targets for bucket: {}",
|
|
],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/notify/src/bucket_config_manager.rs",
|
|
&["Available ARNs: {:?}", "Loaded notification config for bucket: {}"],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/notify/src/rule_engine.rs",
|
|
&[
|
|
"Updated notification rules for bucket: {}",
|
|
"Removed all notification rules for bucket: {}",
|
|
],
|
|
);
|
|
assert_no_unmasked_access_key_logging(
|
|
"crates/audit/src/observability.rs",
|
|
&["Audit configuration reloaded", "Audit system started", "Audit metrics reset"],
|
|
);
|
|
}
|
|
}
|