From: Yehuda Sadeh Date: Sat, 15 Jun 2013 06:35:58 +0000 (-0700) Subject: rgw: fixes for intra-zone object copy X-Git-Tag: v0.67-rc1~128^2~25^2~22 X-Git-Url: http://git-server-git.apps.pok.os.sepia.ceph.com/?a=commitdiff_plain;h=8fa4394f6ae58545c3925fa66dd255959bd11c2d;p=ceph.git rgw: fixes for intra-zone object copy Signed-off-by: Yehuda Sadeh --- diff --git a/src/rgw/rgw_main.cc b/src/rgw/rgw_main.cc index 7a285b175ce..ba894334444 100644 --- a/src/rgw/rgw_main.cc +++ b/src/rgw/rgw_main.cc @@ -340,15 +340,15 @@ void RGWProcess::handle_request(RGWRequest *req) req->log(s, "reading the cors attr"); handler->read_cors_config(); - if (!s->system_request) { - req->log(s, "verifying op permissions"); - ret = op->verify_permission(); - if (ret < 0) { + req->log(s, "verifying op permissions"); + ret = op->verify_permission(); + if (ret < 0) { + if (s->system_request) { + dout(2) << "overriding permissions due to system operation" << dendl; + } else { abort_early(s, ret); goto done; } - } else { - req->log(s, "skipping permissons checks for system request"); } req->log(s, "verifying op params"); diff --git a/src/rgw/rgw_op.cc b/src/rgw/rgw_op.cc index a7ac04977fb..0372e5c3cd9 100644 --- a/src/rgw/rgw_op.cc +++ b/src/rgw/rgw_op.cc @@ -1475,7 +1475,7 @@ int RGWCopyObj::verify_permission() src_bucket = src_bucket_info.bucket; /* get buckets info (source and dest) */ - if (s->local_source) { + if (s->local_source && source_zone.empty()) { rgw_obj src_obj(src_bucket, src_object); store->set_atomic(s->obj_ctx, src_obj); store->set_prefetch_data(s->obj_ctx, src_obj); @@ -1485,7 +1485,8 @@ int RGWCopyObj::verify_permission() if (ret < 0) return ret; - if (!src_policy.verify_permission(s->user.user_id, s->perm_mask, RGW_PERM_READ)) + if (!s->system_request && /* system request overrides permission checks */ + !src_policy.verify_permission(s->user.user_id, s->perm_mask, RGW_PERM_READ)) return -EACCES; } @@ -1509,7 +1510,8 @@ int RGWCopyObj::verify_permission() if (ret < 0) return ret; - if (!dest_bucket_policy.verify_permission(s->user.user_id, s->perm_mask, RGW_PERM_WRITE)) + if (!s->system_request && /* system request overrides permission checks */ + !dest_bucket_policy.verify_permission(s->user.user_id, s->perm_mask, RGW_PERM_WRITE)) return -EACCES; ret = init_dest_policy(); diff --git a/src/rgw/rgw_rados.cc b/src/rgw/rgw_rados.cc index 635608e92f0..3da9f583762 100644 --- a/src/rgw/rgw_rados.cc +++ b/src/rgw/rgw_rados.cc @@ -2193,7 +2193,7 @@ public: /* * prepare attrset, either replace it with new attrs, or keep it (other than acls). */ -static void set_copy_attrs(map& src_attrs, map& attrs, bool replace_attrs) +static void set_copy_attrs(map& src_attrs, map& attrs, bool replace_attrs, bool intra_region) { if (replace_attrs) { if (!attrs[RGW_ATTR_ETAG].length()) @@ -2201,8 +2201,9 @@ static void set_copy_attrs(map& src_attrs, map