Deep-clone the appconfig when getting from cache (#8194)
This commit is contained in:
@@ -272,6 +272,107 @@ spec:
|
||||
assert.True(t, savedAppConfig.Features.EnableSoftwareInventory)
|
||||
}
|
||||
|
||||
func TestApplyAppConfigDryRunIssue(t *testing.T) {
|
||||
// reproduces the bug fixed by https://github.com/fleetdm/fleet/pull/8194
|
||||
_, ds := runServerWithMockedDS(t)
|
||||
|
||||
ds.ListUsersFunc = func(ctx context.Context, opt fleet.UserListOptions) ([]*fleet.User, error) {
|
||||
return userRoleSpecList, nil
|
||||
}
|
||||
|
||||
ds.UserByEmailFunc = func(ctx context.Context, email string) (*fleet.User, error) {
|
||||
if email == "admin1@example.com" {
|
||||
return userRoleSpecList[0], nil
|
||||
}
|
||||
return userRoleSpecList[1], nil
|
||||
}
|
||||
|
||||
ds.NewActivityFunc = func(ctx context.Context, user *fleet.User, activityType string, details *map[string]interface{}) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
var currentAppConfig = &fleet.AppConfig{
|
||||
OrgInfo: fleet.OrgInfo{OrgName: "Fleet"}, ServerSettings: fleet.ServerSettings{ServerURL: "https://example.org"},
|
||||
}
|
||||
ds.AppConfigFunc = func(ctx context.Context) (*fleet.AppConfig, error) {
|
||||
return currentAppConfig, nil
|
||||
}
|
||||
|
||||
ds.SaveAppConfigFunc = func(ctx context.Context, config *fleet.AppConfig) error {
|
||||
currentAppConfig = config
|
||||
return nil
|
||||
}
|
||||
|
||||
// first, set the default app config's agent options as set after fleetctl setup
|
||||
name := writeTmpYml(t, `---
|
||||
apiVersion: v1
|
||||
kind: config
|
||||
spec:
|
||||
agent_options:
|
||||
config:
|
||||
decorators:
|
||||
load:
|
||||
- SELECT uuid AS host_uuid FROM system_info;
|
||||
- SELECT hostname AS hostname FROM system_info;
|
||||
options:
|
||||
disable_distributed: false
|
||||
distributed_interval: 10
|
||||
distributed_plugin: tls
|
||||
distributed_tls_max_attempts: 3
|
||||
logger_tls_endpoint: /api/osquery/log
|
||||
logger_tls_period: 10
|
||||
pack_delimiter: /
|
||||
overrides: {}
|
||||
`)
|
||||
|
||||
assert.Equal(t, "[+] applied fleet config\n", runAppForTest(t, []string{"apply", "-f", name}))
|
||||
|
||||
// then, dry-run a valid app config's agent options, which made the original
|
||||
// app config's agent options invalid JSON (when it shouldn't have modified
|
||||
// it at all - the issue was in the cached_mysql datastore, it did not clone
|
||||
// the app config properly).
|
||||
name = writeTmpYml(t, `---
|
||||
apiVersion: v1
|
||||
kind: config
|
||||
spec:
|
||||
agent_options:
|
||||
overrides:
|
||||
platforms:
|
||||
darwin:
|
||||
auto_table_construction:
|
||||
tcc_system_entries:
|
||||
query: "SELECT service, client, allowed, prompt_count, last_modified FROM access"
|
||||
path: "/Library/Application Support/com.apple.TCC/TCC.db"
|
||||
columns:
|
||||
- "service"
|
||||
- "client"
|
||||
- "allowed"
|
||||
- "prompt_count"
|
||||
- "last_modified"
|
||||
`)
|
||||
|
||||
assert.Equal(t, "[+] would've applied fleet config\n", runAppForTest(t, []string{"apply", "--dry-run", "-f", name}))
|
||||
|
||||
// the saved app config was left unchanged, still equal to the original agent
|
||||
// options
|
||||
got := runAppForTest(t, []string{"get", "config"})
|
||||
assert.Contains(t, got, `agent_options:
|
||||
config:
|
||||
decorators:
|
||||
load:
|
||||
- SELECT uuid AS host_uuid FROM system_info;
|
||||
- SELECT hostname AS hostname FROM system_info;
|
||||
options:
|
||||
disable_distributed: false
|
||||
distributed_interval: 10
|
||||
distributed_plugin: tls
|
||||
distributed_tls_max_attempts: 3
|
||||
logger_tls_endpoint: /api/osquery/log
|
||||
logger_tls_period: 10
|
||||
pack_delimiter: /
|
||||
overrides: {}`)
|
||||
}
|
||||
|
||||
func TestApplyAppConfigUnknownFields(t *testing.T) {
|
||||
_, ds := runServerWithMockedDS(t)
|
||||
|
||||
|
||||
@@ -8,6 +8,7 @@ import (
|
||||
"testing"
|
||||
"time"
|
||||
|
||||
"github.com/fleetdm/fleet/v4/server/datastore/cached_mysql"
|
||||
"github.com/fleetdm/fleet/v4/server/fleet"
|
||||
"github.com/fleetdm/fleet/v4/server/mock"
|
||||
"github.com/fleetdm/fleet/v4/server/service"
|
||||
@@ -47,7 +48,9 @@ func runServerWithMockedDS(t *testing.T, opts ...*service.TestServerOpts) (*http
|
||||
ds.ListUsersFunc = func(ctx context.Context, opt fleet.UserListOptions) ([]*fleet.User, error) {
|
||||
return users, nil
|
||||
}
|
||||
_, server := service.RunServerForTestsWithDS(t, ds, opts...)
|
||||
|
||||
cachedDS := cached_mysql.New(ds)
|
||||
_, server := service.RunServerForTestsWithDS(t, cachedDS, opts...)
|
||||
os.Setenv("FLEET_SERVER_ADDRESS", server.URL)
|
||||
|
||||
return server, ds
|
||||
|
||||
Reference in New Issue
Block a user