From 11f646b051e43e99fd60785c39dc7520f8c7e58c Mon Sep 17 00:00:00 2001 From: Luke McCrone Date: Thu, 27 Feb 2025 20:21:07 -0300 Subject: [PATCH] test: crc64nvme checksum --- .github/workflows/system.yml | 1 + tests/rest_scripts/calculate_crc64nvme.sh | 38 +++++++++++++ tests/rest_scripts/get_object_lock_config.sh | 1 - tests/rest_scripts/init_python_env.sh | 43 +++++++++++++++ tests/rest_scripts/put_object.sh | 8 +++ tests/test_rest.sh | 31 ++--------- tests/test_rest_checksum.sh | 39 ++++++++----- tests/test_rest_versioning.sh | 5 +- tests/util/util_acl.sh | 19 +++++-- tests/util/util_object.sh | 58 +++++++++++++++++--- tests/util/util_policy.sh | 14 +++-- 11 files changed, 195 insertions(+), 62 deletions(-) create mode 100755 tests/rest_scripts/calculate_crc64nvme.sh create mode 100755 tests/rest_scripts/init_python_env.sh diff --git a/.github/workflows/system.yml b/.github/workflows/system.yml index 6db54e6b..70353f0d 100644 --- a/.github/workflows/system.yml +++ b/.github/workflows/system.yml @@ -172,6 +172,7 @@ jobs: VERSIONING_DIR: ${{ github.workspace }}/versioning COMMAND_LOG: command.log TIME_LOG: time.log + PYTHON_ENV_FOLDER: ${{ github.workspace }}/env run: | make testbin export AWS_ACCESS_KEY_ID=ABCDEFGHIJKLMNOPQRST diff --git a/tests/rest_scripts/calculate_crc64nvme.sh b/tests/rest_scripts/calculate_crc64nvme.sh new file mode 100755 index 00000000..d7e90501 --- /dev/null +++ b/tests/rest_scripts/calculate_crc64nvme.sh @@ -0,0 +1,38 @@ +#!/usr/bin/env bash + +# Copyright 2024 Versity Software +# This file is licensed under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http:#www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +source ./tests/rest_scripts/rest.sh + +if ! DEACTIVATE=false source ./tests/rest_scripts/init_python_env.sh; then + log_rest 2 "error initializing python environment" + exit 1 +fi +if ! checksum_decimal=$(python3 -c " +import sys +from awscrt import checksums + +with open(sys.argv[1], 'rb') as f: + print(checksums.crc64nvme(f.read()))" "$DATA_FILE" 2>&1); then + log_rest 2 "error calculating checksum: $checksum_decimal" + exit 1 +fi +log 5 "decimal checksum: $checksum_decimal" +if ! deactivate 1>/dev/null; then + log_rest 2 "error deactivating virtual environment" + exit 1 +fi +checksum_hash=$(printf "%016x" "$checksum_decimal" | xxd -r -p | base64) +echo "$checksum_hash" \ No newline at end of file diff --git a/tests/rest_scripts/get_object_lock_config.sh b/tests/rest_scripts/get_object_lock_config.sh index c33eb07e..a8147add 100755 --- a/tests/rest_scripts/get_object_lock_config.sh +++ b/tests/rest_scripts/get_object_lock_config.sh @@ -28,7 +28,6 @@ if ! build_canonical_request "${canonical_request_data[@]}"; then log_rest 2 "error building request" exit 1 fi -echo "$canonical_request" > "cr.txt" # shellcheck disable=SC2119 create_canonical_hash_sts_and_signature diff --git a/tests/rest_scripts/init_python_env.sh b/tests/rest_scripts/init_python_env.sh new file mode 100755 index 00000000..fefcc6c5 --- /dev/null +++ b/tests/rest_scripts/init_python_env.sh @@ -0,0 +1,43 @@ +#!/usr/bin/env bash + +# Copyright 2024 Versity Software +# This file is licensed under the Apache License, Version 2.0 +# (the "License"); you may not use this file except in compliance +# with the License. You may obtain a copy of the License at +# +# http:#www.apache.org/licenses/LICENSE-2.0 +# +# Unless required by applicable law or agreed to in writing, +# software distributed under the License is distributed on an +# "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY +# KIND, either express or implied. See the License for the +# specific language governing permissions and limitations +# under the License. + +source ./tests/rest_scripts/rest.sh + +deactivate=${DEACTIVATE:=true} + +if [ -z "$PYTHON_ENV_FOLDER" ] && [ -z "$TEST_FILE_FOLDER" ]; then + log_rest 2 "python virtual env setup requires either PYTHON_ENV_FOLDER or TEST_FILE_FOLDER param" + exit 1 +fi +python_env_folder=${PYTHON_ENV_FOLDER:=${TEST_FILE_FOLDER}/env} +if [ ! -d "$python_env_folder" ] && ! python3 -m venv "$python_env_folder"; then + log_rest 2 "error creating python virtual environment" + exit 1 +fi +if ! source "$python_env_folder/bin/activate"; then + log_rest 2 "error activating virtual environment" + exit 1 +fi +if ! python3 -m pip list | grep awscrt 1>/dev/null; then + if ! python3 -m pip install awscrt 1>/dev/null; then + log_rest 2 "error installing awscrt" + exit 1 + fi +fi +if [ "$deactivate" == "true" ] && ! deactivate; then + log_rest 2 "error deactivating" + exit 1 +fi \ No newline at end of file diff --git a/tests/rest_scripts/put_object.sh b/tests/rest_scripts/put_object.sh index f4085e48..21336de8 100755 --- a/tests/rest_scripts/put_object.sh +++ b/tests/rest_scripts/put_object.sh @@ -51,6 +51,14 @@ elif [ "$checksum_type" == "crc32" ]; then checksum_hash="$(gzip -c -1 "$data_file" | tail -c8 | od -t x4 -N 4 -A n | awk '{print $1}' | xxd -r -p | base64)" fi cr_data+=("x-amz-checksum-crc32:$checksum_hash") +elif [ "$checksum_type" == "crc64nvme" ]; then + if [ -z "$checksum_hash" ]; then + if ! checksum_hash=$(DATA_FILE="$data_file" TEST_FILE_FOLDER="$TEST_FILE_FOLDER" ./tests/rest_scripts/calculate_crc64nvme.sh 2>&1); then + log_rest 2 "error calculating crc64nvme checksum: $checksum_hash" + exit 1 + fi + fi + cr_data+=("x-amz-checksum-crc64nvme:$checksum_hash") fi cr_data+=("x-amz-content-sha256:$payload_hash" "x-amz-date:$current_date_time") build_canonical_request "${cr_data[@]}" diff --git a/tests/test_rest.sh b/tests/test_rest.sh index e806e575..d477703f 100755 --- a/tests/test_rest.sh +++ b/tests/test_rest.sh @@ -53,9 +53,9 @@ source ./tests/util/util_versioning.sh source ./tests/util/util_xml.sh export RUN_USERS=true +test_file="test_file" @test "test_rest_list_objects" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -75,7 +75,6 @@ export RUN_USERS=true } @test "test_rest_delete_object" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -96,7 +95,6 @@ export RUN_USERS=true } @test "test_rest_tagging" { - test_file="test_file" test_key="TestKey" test_value="TestValue" @@ -120,7 +118,6 @@ export RUN_USERS=true } @test "test_rest_retention" { - test_file="test_file" test_key="TestKey" test_value="TestValue" @@ -168,7 +165,6 @@ export RUN_USERS=true } @test "REST - legal hold, get without config" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -180,8 +176,6 @@ export RUN_USERS=true } @test "REST - multipart upload create then abort" { - test_file="test_file" - run setup_bucket "s3api" "$BUCKET_ONE_NAME" assert_success @@ -190,7 +184,6 @@ export RUN_USERS=true } @test "REST - multipart upload create, list parts" { - test_file="test_file" run setup_bucket_and_large_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -212,7 +205,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1000" fi - test_file="test_file" run setup_bucket_and_large_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -230,7 +222,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1001" fi - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -245,7 +236,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1006" fi - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -320,7 +310,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/993" fi - test_file="test_file" test_file_two="test_file_2" test_file_three="test_file_3" run setup_bucket_and_files "s3api" "$BUCKET_ONE_NAME" "$test_file" "$test_file_two" "$test_file_three" @@ -348,7 +337,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/999" fi - test_file="test_file" test_file_two="test_file_2" run setup_bucket "s3api" "$BUCKET_ONE_NAME" "$test_file" "$test_file_two" assert_success @@ -367,7 +355,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1008" fi - test_file="test_file" run setup_bucket_and_large_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -376,7 +363,6 @@ export RUN_USERS=true } @test "REST - upload part copy" { - test_file="test_file" run setup_bucket_and_large_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -391,7 +377,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1018" fi - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -426,27 +411,26 @@ export RUN_USERS=true } @test "REST - delete objects command" { - test_file_one="test_file" test_file_two="test_file_two" - run setup_bucket_and_files "$BUCKET_ONE_NAME" "$test_file_one" "$test_file_two" + run setup_bucket_and_files "$BUCKET_ONE_NAME" "$test_file" "$test_file_two" assert_success - run put_object "s3api" "$TEST_FILE_FOLDER/$test_file_one" "$BUCKET_ONE_NAME" "$test_file_one" + run put_object "s3api" "$TEST_FILE_FOLDER/$test_file" "$BUCKET_ONE_NAME" "$test_file" assert_success run put_object "s3api" "$TEST_FILE_FOLDER/$test_file_two" "$BUCKET_ONE_NAME" "$test_file_two" assert_success - run verify_object_exists "$BUCKET_ONE_NAME" "$test_file_one" + run verify_object_exists "$BUCKET_ONE_NAME" "$test_file" assert_success run verify_object_exists "$BUCKET_ONE_NAME" "$test_file_two" assert_success - run delete_objects_verify_success "$BUCKET_ONE_NAME" "$test_file_one" "$test_file_two" + run delete_objects_verify_success "$BUCKET_ONE_NAME" "$test_file" "$test_file_two" assert_success - run verify_object_not_found "$BUCKET_ONE_NAME" "$test_file_one" + run verify_object_not_found "$BUCKET_ONE_NAME" "$test_file" assert_success run verify_object_not_found "$BUCKET_ONE_NAME" "$test_file_two" @@ -457,7 +441,6 @@ export RUN_USERS=true if [ "$DIRECT" != "true" ]; then skip "https://github.com/versity/versitygw/issues/1043" fi - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -481,7 +464,6 @@ export RUN_USERS=true assert_success fi - test_file="test_file" run create_test_files "$test_file" assert_success @@ -508,7 +490,6 @@ export RUN_USERS=true assert_success fi - test_file="test_file" run create_test_files "$test_file" assert_success diff --git a/tests/test_rest_checksum.sh b/tests/test_rest_checksum.sh index 5d060528..f5f5c589 100755 --- a/tests/test_rest_checksum.sh +++ b/tests/test_rest_checksum.sh @@ -21,8 +21,9 @@ source ./tests/setup.sh source ./tests/util/util_head_object.sh source ./tests/util/util_setup.sh +test_file="test_file" + @test "REST - HeadObject returns x-amz-checksum-sha256" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -34,7 +35,6 @@ source ./tests/util/util_setup.sh } @test "REST - PutObject rejects invalid sha256 checksum" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -43,7 +43,6 @@ source ./tests/util/util_setup.sh } @test "REST - PutObject rejects incorrect sha256 checksum" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -51,17 +50,7 @@ source ./tests/util/util_setup.sh assert_success } -@test "REST - crc32 checksum - success" { - test_file="test_file" - run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" - assert_success - - run put_object_rest_checksum "$TEST_FILE_FOLDER/$test_file" "$BUCKET_ONE_NAME" "$test_file" "crc32" - assert_success -} - @test "REST - crc32 checksum - correct" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -71,3 +60,27 @@ source ./tests/util/util_setup.sh run check_checksum_rest_crc32 "$BUCKET_ONE_NAME" "$test_file" "$TEST_FILE_FOLDER/$test_file" assert_success } + +@test "REST - crc32 checksum - incorrect" { + run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" + assert_success + + run put_object_rest_crc32_incorrect "$TEST_FILE_FOLDER/$test_file" "$BUCKET_ONE_NAME" "$test_file" + assert_success +} + +@test "REST - crc64nvme checksum - correct" { + run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" + assert_success + + run put_object_rest_checksum "$TEST_FILE_FOLDER/$test_file" "$BUCKET_ONE_NAME" "$test_file" "crc64nvme" + assert_success +} + +@test "REST - crc64nvme checksum - incorrect" { + run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" + assert_success + + run put_object_rest_crc64nvme_incorrect "$TEST_FILE_FOLDER/$test_file" "$BUCKET_ONE_NAME" "$test_file" + assert_success +} diff --git a/tests/test_rest_versioning.sh b/tests/test_rest_versioning.sh index de07386d..e72aca74 100755 --- a/tests/test_rest_versioning.sh +++ b/tests/test_rest_versioning.sh @@ -23,6 +23,8 @@ source ./tests/commands/put_object.sh source ./tests/util/util_rest.sh source ./tests/util/util_setup.sh +test_file="test_file" + @test "REST - check, enable, suspend versioning" { run setup_bucket "s3api" "$BUCKET_ONE_NAME" assert_success @@ -46,7 +48,6 @@ source ./tests/util/util_setup.sh } @test "test_rest_versioning" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -70,7 +71,6 @@ source ./tests/util/util_setup.sh } @test "versioning - add version, then delete and check for marker" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success @@ -88,7 +88,6 @@ source ./tests/util/util_setup.sh } @test "versioning - retrieve after delete" { - test_file="test_file" run setup_bucket_and_file "$BUCKET_ONE_NAME" "$test_file" assert_success diff --git a/tests/util/util_acl.sh b/tests/util/util_acl.sh index 6e67035d..87e4c1d0 100644 --- a/tests/util/util_acl.sh +++ b/tests/util/util_acl.sh @@ -216,6 +216,17 @@ get_check_acl_after_policy() { fi } +check_direct_display_name() { + if ! display_name=$(echo "$owner" | xmllint --xpath '//*[local-name()="DisplayName"]/text()' - 2>&1); then + log 2 "error getting display name: $display_name" + return 1 + fi + if [ "$display_name" != "$DIRECT_DISPLAY_NAME" ]; then + log 2 "display name mismatch (expected '$DIRECT_DISPLAY_NAME', actual '$display_name')" + return 1 + fi +} + get_and_check_acl_rest() { if [ $# -ne 1 ]; then log 2 "'get_and_check_acl_rest' requires bucket name" @@ -239,12 +250,8 @@ get_and_check_acl_rest() { return 1 fi if [ "$DIRECT" == "true" ]; then - if ! display_name=$(echo "$owner" | xmllint --xpath '//*[local-name()="DisplayName"]/text()' - 2>&1); then - log 2 "error getting display name: $display_name" - return 1 - fi - if [ "$display_name" != "$DIRECT_DISPLAY_NAME" ]; then - log 2 "display name mismatch (expected '$DIRECT_DISPLAY_NAME', actual '$display_name')" + if ! check_direct_display_name; then + log 2 "error checking direct display name" return 1 fi else diff --git a/tests/util/util_object.sh b/tests/util/util_object.sh index 12ea09a4..9e899537 100644 --- a/tests/util/util_object.sh +++ b/tests/util/util_object.sh @@ -297,12 +297,12 @@ list_and_check_directory_obj() { return 0 } -check_sha256_invalid_or_incorrect() { - if [ $# -ne 5 ]; then - log 2 "'check_sha256_invalid_or_incorrect' requires data file, bucket name, key, checksum, expected error" +check_checksum_invalid_or_incorrect() { + if [ $# -ne 6 ]; then + log 2 "'check_sha256_invalid_or_incorrect' requires data file, bucket name, key, checksum type, checksum, expected error" return 1 fi - if ! result=$(COMMAND_LOG="$COMMAND_LOG" DATA_FILE="$1" BUCKET_NAME="$2" OBJECT_KEY="$3" OUTPUT_FILE="$TEST_FILE_FOLDER/result.txt" CHECKSUM_TYPE="sha256" CHECKSUM="$4" ./tests/rest_scripts/put_object.sh 2>&1); then + if ! result=$(COMMAND_LOG="$COMMAND_LOG" DATA_FILE="$1" BUCKET_NAME="$2" OBJECT_KEY="$3" OUTPUT_FILE="$TEST_FILE_FOLDER/result.txt" CHECKSUM_TYPE="$4" CHECKSUM="$5" ./tests/rest_scripts/put_object.sh 2>&1); then log 2 "error: $result" return 1 fi @@ -310,7 +310,7 @@ check_sha256_invalid_or_incorrect() { log 2 "expected response code of '400', was '$result' (response: $(cat "$TEST_FILE_FOLDER/result.txt")" return 1 fi - if ! check_xml_element "$TEST_FILE_FOLDER/result.txt" "$5" "Error" "Message"; then + if ! check_xml_element "$TEST_FILE_FOLDER/result.txt" "$6" "Error" "Message"; then log 2 "xml error message mismatch" return 1 fi @@ -322,12 +322,13 @@ put_object_rest_checksum() { log 2 "'put_object_rest_sha256_checksum' requires data file, bucket name, key, checksum type" return 1 fi - if ! result=$(COMMAND_LOG="$COMMAND_LOG" DATA_FILE="$1" BUCKET_NAME="$2" OBJECT_KEY="$3" OUTPUT_FILE="$TEST_FILE_FOLDER/result.txt" CHECKSUM_TYPE="$4" ./tests/rest_scripts/put_object.sh 2>&1); then + # shellcheck disable=SC2097,SC2098 + if ! result=$(COMMAND_LOG="$COMMAND_LOG" DATA_FILE="$1" BUCKET_NAME="$2" OBJECT_KEY="$3" TEST_FILE_FOLDER="$TEST_FILE_FOLDER" OUTPUT_FILE="$TEST_FILE_FOLDER/result.txt" CHECKSUM_TYPE="$4" ./tests/rest_scripts/put_object.sh 2>&1); then log 2 "error: $result" return 1 fi if [ "$result" != "200" ]; then - log 2 "expected response code of '200', was '$result'" + log 2 "expected response code of '200', was '$result' ($(cat "$TEST_FILE_FOLDER/result.txt"))" return 1 fi log 5 "result: $(cat "$TEST_FILE_FOLDER/result.txt")" @@ -339,7 +340,7 @@ put_object_rest_sha256_invalid() { log 2 "'put_object_rest_sha256_invalid' requires data file, bucket name, key" return 1 fi - if ! check_sha256_invalid_or_incorrect "$1" "$2" "$3" "dummy" "Value for x-amz-checksum-sha256 header is invalid."; then + if ! check_checksum_invalid_or_incorrect "$1" "$2" "$3" "sha256" "dummy" "Value for x-amz-checksum-sha256 header is invalid."; then log 2 "error checking checksum" return 1 fi @@ -357,7 +358,7 @@ put_object_rest_sha256_incorrect() { error_message="The sha256 you specified did not match the calculated checksum." fi incorrect_checksum="$(echo -n "dummy" | sha256sum | awk '{print $1}' | xxd -r -p | base64)" - if ! check_sha256_invalid_or_incorrect "$1" "$2" "$3" "$incorrect_checksum" "$error_message"; then + if ! check_checksum_invalid_or_incorrect "$1" "$2" "$3" "sha256" "$incorrect_checksum" "$error_message"; then log 2 "error checking checksum" return 1 fi @@ -379,3 +380,42 @@ put_object_rest_chunked_payload_type_without_content_length() { fi return 0 } + +put_object_rest_crc32_incorrect() { + if [ $# -ne 3 ]; then + log 2 "'put_object_rest_crc32_incorrect' requires data file, bucket name, key" + return 1 + fi + if [ "$DIRECT" == "true" ]; then + error_message="The CRC32 you specified did not match the calculated checksum." + else + error_message="The crc32 you specified did not match the calculated checksum." + fi + incorrect_checksum="$(echo -n "dummy" | gzip -c -1 | tail -c8 | od -t x4 -N 4 -A n | awk '{print $1}' | xxd -r -p | base64)" + if ! check_checksum_invalid_or_incorrect "$1" "$2" "$3" "crc32" "$incorrect_checksum" "$error_message"; then + log 2 "error checking checksum" + return 1 + fi + return 0 +} + +put_object_rest_crc64nvme_incorrect() { + if [ $# -ne 3 ]; then + log 2 "'put_object_rest_crc64nvme_incorrect' requires data file, bucket name, key" + return 1 + fi + if [ "$DIRECT" == "true" ]; then + error_message="The CRC64NVME you specified did not match the calculated checksum." + else + error_message="The crc64nvme you specified did not match the calculated checksum." + fi + if ! incorrect_checksum=$(DATA_FILE=<(echo -n "dummy") TEST_FILE_FOLDER="$TEST_FILE_FOLDER" ./tests/rest_scripts/calculate_crc64nvme.sh 2>&1); then + log 2 "error calculating checksum: $incorrect_checksum" + return 1 + fi + if ! check_checksum_invalid_or_incorrect "$1" "$2" "$3" "crc64nvme" "$incorrect_checksum" "$error_message"; then + log 2 "error checking checksum" + return 1 + fi + return 0 +} diff --git a/tests/util/util_policy.sh b/tests/util/util_policy.sh index 9b386868..b59b61aa 100644 --- a/tests/util/util_policy.sh +++ b/tests/util/util_policy.sh @@ -42,6 +42,14 @@ check_for_empty_policy() { return 0 } +add_direct_user_to_principal() { + if [ "${principals[$idx]}" == "*" ]; then + modified_principal+="{\"AWS\": \"arn:aws:iam::$DIRECT_AWS_USER_ID:user/$DIRECT_S3_ROOT_ACCOUNT_NAME\"}" + else + modified_principal+="{\"AWS\": \"arn:aws:iam::$DIRECT_AWS_USER_ID:user/${principals[$idx]}\"}" + fi +} + get_modified_principal() { log 6 "get_modified_principal" if [ $# -ne 1 ]; then @@ -55,11 +63,7 @@ get_modified_principal() { fi for ((idx=0; idx<${#principals[@]}; idx++)); do if [ "$DIRECT" == "true" ]; then - if [ "${principals[$idx]}" == "*" ]; then - modified_principal+="{\"AWS\": \"arn:aws:iam::$DIRECT_AWS_USER_ID:user/$DIRECT_S3_ROOT_ACCOUNT_NAME\"}" - else - modified_principal+="{\"AWS\": \"arn:aws:iam::$DIRECT_AWS_USER_ID:user/${principals[$idx]}\"}" - fi + add_direct_user_to_principal else # shellcheck disable=SC2089 modified_principal+="\"${principals[$idx]}\""