Skip to content

Commit

Permalink
auth: correct initialization in NewAuthStore()
Browse files Browse the repository at this point in the history
Because of my own silly mistake, current NewAuthStore() doesn't
initialize authStore in a correct manner. For example, after recovery
from snapshot, it cannot revive the flag of enabled/disabled. This
commit fixes the problem.

Fix #7165
  • Loading branch information
mitake authored and gyuho committed Feb 14, 2017
1 parent 4962c5c commit 9e81b00
Show file tree
Hide file tree
Showing 2 changed files with 35 additions and 14 deletions.
46 changes: 32 additions & 14 deletions auth/store.go
Original file line number Diff line number Diff line change
Expand Up @@ -177,6 +177,17 @@ type authStore struct {
indexWaiter func(uint64) <-chan struct{}
}

func newDeleterFunc(as *authStore) func(string) {
return func(t string) {
as.simpleTokensMu.Lock()
defer as.simpleTokensMu.Unlock()
if username, ok := as.simpleTokens[t]; ok {
plog.Infof("deleting token %s for user %s", t, username)
delete(as.simpleTokens, t)
}
}
}

func (as *authStore) AuthEnable() error {
as.enabledMu.Lock()
defer as.enabledMu.Unlock()
Expand Down Expand Up @@ -205,15 +216,7 @@ func (as *authStore) AuthEnable() error {

as.enabled = true

tokenDeleteFunc := func(t string) {
as.simpleTokensMu.Lock()
defer as.simpleTokensMu.Unlock()
if username, ok := as.simpleTokens[t]; ok {
plog.Infof("deleting token %s for user %s", t, username)
delete(as.simpleTokens, t)
}
}
as.simpleTokenKeeper = NewSimpleTokenTTLKeeper(tokenDeleteFunc)
as.simpleTokenKeeper = NewSimpleTokenTTLKeeper(newDeleterFunc(as))

as.rangePermCache = make(map[string]*unifiedRangePermissions)

Expand Down Expand Up @@ -887,11 +890,25 @@ func NewAuthStore(be backend.Backend, indexWaiter func(uint64) <-chan struct{})
tx.UnsafeCreateBucket(authUsersBucketName)
tx.UnsafeCreateBucket(authRolesBucketName)

enabled := false
_, vs := tx.UnsafeRange(authBucketName, enableFlagKey, nil, 0)
if len(vs) == 1 {
if bytes.Equal(vs[0], authEnabled) {
enabled = true
}
}

as := &authStore{
be: be,
simpleTokens: make(map[string]string),
revision: 0,
indexWaiter: indexWaiter,
be: be,
simpleTokens: make(map[string]string),
revision: getRevision(tx),
indexWaiter: indexWaiter,
enabled: enabled,
rangePermCache: make(map[string]*unifiedRangePermissions),
}

if enabled {
as.simpleTokenKeeper = NewSimpleTokenTTLKeeper(newDeleterFunc(as))
}

as.commitRevision(tx)
Expand Down Expand Up @@ -921,7 +938,8 @@ func (as *authStore) commitRevision(tx backend.BatchTx) {
func getRevision(tx backend.BatchTx) uint64 {
_, vs := tx.UnsafeRange(authBucketName, []byte(revisionKey), nil, 0)
if len(vs) != 1 {
plog.Panicf("failed to get the key of auth store revision")
// this can happen in the initialization phase
return 0
}

return binary.BigEndian.Uint64(vs[0])
Expand Down
3 changes: 3 additions & 0 deletions auth/store_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -305,6 +305,9 @@ func TestRecoverFromSnapshot(t *testing.T) {
as.Close()

as2 := NewAuthStore(as.be, dummyIndexWaiter)
defer func(a *authStore) {
a.Close()
}(as2)

if !as2.isAuthEnabled() {
t.Fatal("recovering authStore from existing backend failed")
Expand Down

0 comments on commit 9e81b00

Please sign in to comment.