fix: 修复写队列 busy 恢复、关闭安全、备份与配置构建问题
This commit is contained in:
+1
-1
@@ -93,7 +93,7 @@ func cmdAdminSetPassword(args []string) error {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
if err := store.SetAdminPasswordHash(ctx, db.Write, phc); err != nil {
|
||||
if err := db.ResetAdminPassword(ctx, phc); err != nil {
|
||||
return err
|
||||
}
|
||||
fmt.Fprintln(os.Stderr, "admin password updated")
|
||||
|
||||
+24
-3
@@ -19,6 +19,25 @@ func cmdBackup(args []string) error {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
dataAbs, err := filepath.Abs(cfg.DataDir)
|
||||
if err != nil {
|
||||
return fmt.Errorf("resolve data_dir: %w", err)
|
||||
}
|
||||
srcAbs, err := filepath.Abs(filepath.Join(dataAbs, store.DBFileName))
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
st, err := os.Stat(srcAbs)
|
||||
if err != nil {
|
||||
if os.IsNotExist(err) {
|
||||
return fmt.Errorf("database not found: %s", srcAbs)
|
||||
}
|
||||
return fmt.Errorf("stat database %s: %w", srcAbs, err)
|
||||
}
|
||||
if st.IsDir() {
|
||||
return fmt.Errorf("database path is a directory: %s", srcAbs)
|
||||
}
|
||||
|
||||
if dir := filepath.Dir(outPath); dir != "" && dir != "." {
|
||||
if mkErr := os.MkdirAll(dir, 0o755); mkErr != nil {
|
||||
return fmt.Errorf("mkdir backup dir: %w", mkErr)
|
||||
@@ -29,8 +48,7 @@ func cmdBackup(args []string) error {
|
||||
return err
|
||||
}
|
||||
ctx := context.Background()
|
||||
// 对运行中的库:单独打开写连接执行 VACUUM INTO(可与 serve 并存,WAL 下安全)。
|
||||
write, err := store.OpenWriter(cfg.DataDir, cfg.SQLiteSynchronous)
|
||||
write, err := store.OpenExistingWriter(dataAbs, cfg.SQLiteSynchronous)
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
@@ -38,7 +56,10 @@ func cmdBackup(args []string) error {
|
||||
if err := store.VacuumInto(ctx, write, filepath.ToSlash(absOut)); err != nil {
|
||||
return err
|
||||
}
|
||||
fmt.Fprintf(os.Stderr, "backup written to %s\n", absOut)
|
||||
if chErr := os.Chmod(absOut, 0o600); chErr != nil {
|
||||
return fmt.Errorf("chmod backup: %w", chErr)
|
||||
}
|
||||
fmt.Fprintf(os.Stderr, "backup written from %s to %s\n", srcAbs, absOut)
|
||||
return nil
|
||||
}
|
||||
|
||||
|
||||
@@ -3,8 +3,13 @@ package main
|
||||
import (
|
||||
"bytes"
|
||||
"context"
|
||||
"io"
|
||||
"net/http"
|
||||
"net/http/cookiejar"
|
||||
"os"
|
||||
"os/exec"
|
||||
"path/filepath"
|
||||
"runtime"
|
||||
"strings"
|
||||
"testing"
|
||||
"time"
|
||||
@@ -108,6 +113,92 @@ func TestBackupVacuumInto(t *testing.T) {
|
||||
}
|
||||
}
|
||||
|
||||
func TestBackupMissingDB(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
path := writeTestConfig(t, dir)
|
||||
t.Setenv("NIXMSG_CONFIG", path)
|
||||
|
||||
out := filepath.Join(dir, "copy.db")
|
||||
err := cmdBackup([]string{"--out", out})
|
||||
if err == nil || !strings.Contains(err.Error(), "database not found") {
|
||||
t.Fatalf("want database not found, got %v", err)
|
||||
}
|
||||
if _, statErr := os.Stat(filepath.Join(dir, store.DBFileName)); !os.IsNotExist(statErr) {
|
||||
t.Fatalf("backup must not create %s: %v", store.DBFileName, statErr)
|
||||
}
|
||||
}
|
||||
|
||||
func TestAdminSetPasswordClearsSessions(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
cfgPath := writeTestConfig(t, dir)
|
||||
initAdminForTest(t, dir)
|
||||
t.Setenv("NIXMSG_CONFIG", cfgPath)
|
||||
|
||||
cfg, err := loadAndValidateConfig()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
ctx, cancel := context.WithCancel(context.Background())
|
||||
defer cancel()
|
||||
errCh := make(chan error, 1)
|
||||
go func() { errCh <- runServe(ctx, cfg) }()
|
||||
addr := waitListenAddr(t, dir, 15*time.Second)
|
||||
base := "http://" + addr
|
||||
|
||||
jar, err := cookiejar.New(nil)
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
client := &http.Client{Jar: jar, Timeout: 10 * time.Second}
|
||||
loginBody := `{"username":"admin","password":"test-admin-password-xx"}`
|
||||
resp, err := client.Post(base+"/api/admin/login", "application/json", strings.NewReader(loginBody))
|
||||
if err != nil {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatal(err)
|
||||
}
|
||||
_, _ = io.ReadAll(resp.Body)
|
||||
_ = resp.Body.Close()
|
||||
if resp.StatusCode != http.StatusOK {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatalf("login status=%d", resp.StatusCode)
|
||||
}
|
||||
|
||||
me, err := client.Get(base + "/api/admin/me")
|
||||
if err != nil {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatal(err)
|
||||
}
|
||||
_ = me.Body.Close()
|
||||
if me.StatusCode != http.StatusOK {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatalf("me before set-password status=%d", me.StatusCode)
|
||||
}
|
||||
|
||||
if err := cmdAdminSetPassword([]string{"--password", "long-enough-password"}); err != nil {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
me2, err := client.Get(base + "/api/admin/me")
|
||||
if err != nil {
|
||||
cancel()
|
||||
<-errCh
|
||||
t.Fatal(err)
|
||||
}
|
||||
body, _ := io.ReadAll(me2.Body)
|
||||
_ = me2.Body.Close()
|
||||
cancel()
|
||||
<-errCh
|
||||
if me2.StatusCode != http.StatusUnauthorized {
|
||||
t.Fatalf("want 401 after set-password, got %d body=%s", me2.StatusCode, body)
|
||||
}
|
||||
}
|
||||
|
||||
func TestHealthcheck(t *testing.T) {
|
||||
dir := t.TempDir()
|
||||
cfgPath := writeTestConfig(t, dir)
|
||||
@@ -151,3 +242,48 @@ func TestParseSetPasswordArgs(t *testing.T) {
|
||||
t.Fatalf("pass=%q err=%v", pass, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestCmdVersionPrintsInjected(t *testing.T) {
|
||||
old := Version
|
||||
Version = "d05-injected"
|
||||
defer func() { Version = old }()
|
||||
|
||||
r, w, err := os.Pipe()
|
||||
if err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
oldOut := os.Stdout
|
||||
os.Stdout = w
|
||||
cmdVersion(nil)
|
||||
_ = w.Close()
|
||||
os.Stdout = oldOut
|
||||
var buf bytes.Buffer
|
||||
_, _ = buf.ReadFrom(r)
|
||||
_ = r.Close()
|
||||
if !strings.Contains(buf.String(), "d05-injected") {
|
||||
t.Fatalf("version output=%q", buf.String())
|
||||
}
|
||||
}
|
||||
|
||||
func TestGoBuildInjectsVersion(t *testing.T) {
|
||||
_, thisFile, _, ok := runtime.Caller(0)
|
||||
if !ok {
|
||||
t.Fatal("runtime.Caller")
|
||||
}
|
||||
pkgDir := filepath.Dir(thisFile)
|
||||
out := filepath.Join(t.TempDir(), "nixmsg-d05-version.exe")
|
||||
build := exec.Command("go", "build", "-ldflags", "-X main.Version=d05-ldflags", "-o", out)
|
||||
build.Dir = pkgDir
|
||||
build.Env = append(os.Environ(), "CGO_ENABLED=0")
|
||||
if b, err := build.CombinedOutput(); err != nil {
|
||||
t.Fatalf("go build: %v\n%s", err, b)
|
||||
}
|
||||
run := exec.Command(out, "version")
|
||||
got, err := run.CombinedOutput()
|
||||
if err != nil {
|
||||
t.Fatalf("version: %v\n%s", err, got)
|
||||
}
|
||||
if !strings.Contains(string(got), "d05-ldflags") {
|
||||
t.Fatalf("version output=%q", got)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,6 +1,7 @@
|
||||
package main
|
||||
|
||||
import (
|
||||
"crypto/tls"
|
||||
"fmt"
|
||||
"io"
|
||||
"net"
|
||||
@@ -25,8 +26,15 @@ func cmdHealthcheck(_ []string) error {
|
||||
if err != nil {
|
||||
return err
|
||||
}
|
||||
url := "http://" + addr + "/healthz"
|
||||
client := &http.Client{Timeout: 3 * time.Second}
|
||||
scheme := "http"
|
||||
if healthcheckUseHTTPS(cfg) {
|
||||
scheme = "https"
|
||||
client.Transport = &http.Transport{
|
||||
TLSClientConfig: &tls.Config{InsecureSkipVerify: true}, // 本机 HEALTHCHECK,自签证书可接受
|
||||
}
|
||||
}
|
||||
url := scheme + "://" + addr + "/healthz"
|
||||
resp, err := client.Get(url)
|
||||
if err != nil {
|
||||
return fmt.Errorf("healthcheck %s: %w", url, err)
|
||||
@@ -39,6 +47,12 @@ func cmdHealthcheck(_ []string) error {
|
||||
return nil
|
||||
}
|
||||
|
||||
func healthcheckUseHTTPS(cfg config.Config) bool {
|
||||
cert := strings.TrimSpace(cfg.TLS.CertFile)
|
||||
key := strings.TrimSpace(cfg.TLS.KeyFile)
|
||||
return cert != "" && key != "" && !cfg.TLS.AllowPlaintext
|
||||
}
|
||||
|
||||
func resolveHealthAddr(dataDir, listen string) (string, error) {
|
||||
path := filepath.Join(dataDir, "listen.addr")
|
||||
if b, err := os.ReadFile(path); err == nil {
|
||||
|
||||
@@ -54,3 +54,34 @@ func TestCmdHealthcheckOK(t *testing.T) {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestCmdHealthcheckHTTPS(t *testing.T) {
|
||||
srv := httptest.NewTLSServer(http.HandlerFunc(func(w http.ResponseWriter, _ *http.Request) {
|
||||
w.WriteHeader(http.StatusOK)
|
||||
_, _ = w.Write([]byte("ok"))
|
||||
}))
|
||||
t.Cleanup(srv.Close)
|
||||
|
||||
dir := t.TempDir()
|
||||
hostPort := srv.Listener.Addr().String()
|
||||
if err := os.WriteFile(filepath.Join(dir, "listen.addr"), []byte(hostPort+"\n"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
cert := filepath.Join(dir, "cert.pem")
|
||||
key := filepath.Join(dir, "key.pem")
|
||||
if err := os.WriteFile(cert, []byte("dummy"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(key, []byte("dummy"), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
cfgPath := filepath.Join(dir, "config.yaml")
|
||||
body := "listen: \":0\"\ndata_dir: \"" + filepath.ToSlash(dir) + "\"\ntls:\n cert_file: \"" + filepath.ToSlash(cert) + "\"\n key_file: \"" + filepath.ToSlash(key) + "\"\n allow_plaintext: false\n"
|
||||
if err := os.WriteFile(cfgPath, []byte(body), 0o644); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
t.Setenv("NIXMSG_CONFIG", cfgPath)
|
||||
if err := cmdHealthcheck(nil); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user