Log a refused wording without what it quotes, and keep the secret-given words within bounds
The reviewer found that the logged reason quoted the refused fragment: a hash-shaped secret would reach the journal, and a changing clock time defeated the once-per-kind dedupe. The reason is now logged without its quoted fragment, the test resets the dedupe so it repeats, and a module name too long for the headline falls back to the machine.
This commit is contained in:
@@ -151,11 +151,17 @@ func unworded(o Observation, why string) {
|
||||
Unworded(o, why)
|
||||
return
|
||||
}
|
||||
if _, seen := loggedUnworded.LoadOrStore(o.Kind+"\x00"+why, true); !seen {
|
||||
log.Printf("the condition kind %q is said in the scope's words, not its own: %s", o.Kind, why)
|
||||
// The reason without what it quotes of the words: a quoted fragment may be a hash-shaped secret, and a
|
||||
// fragment that changes (a clock time) would log a new line every time.
|
||||
reason := quotedFragment.ReplaceAllString(why, "")
|
||||
if _, seen := loggedUnworded.LoadOrStore(o.Kind+"\x00"+reason, true); !seen {
|
||||
log.Printf("the condition kind %q is said in the scope's words, not its own: %s", o.Kind, reason)
|
||||
}
|
||||
}
|
||||
|
||||
// quotedFragment is what a reason of the plain rule quotes of the words it refused, at its end.
|
||||
var quotedFragment = regexp.MustCompile(` \([^()]*\)$`)
|
||||
|
||||
// The plain rule's shapes.
|
||||
var (
|
||||
hexID = regexp.MustCompile(`\b[0-9a-f]{7,40}\b`)
|
||||
|
||||
@@ -4,7 +4,6 @@ import (
|
||||
"bytes"
|
||||
"encoding/json"
|
||||
"log"
|
||||
"os"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
@@ -256,18 +255,28 @@ func TestBorrowedWordsAreLogged(t *testing.T) {
|
||||
before := Unworded
|
||||
Unworded = nil
|
||||
t.Cleanup(func() { Unworded = before })
|
||||
loggedUnworded.Clear()
|
||||
t.Cleanup(loggedUnworded.Clear)
|
||||
var out bytes.Buffer
|
||||
writer := log.Writer()
|
||||
log.SetOutput(&out)
|
||||
t.Cleanup(func() { log.SetOutput(os.Stderr) })
|
||||
for i := 0; i < 3; i++ {
|
||||
t.Cleanup(func() { log.SetOutput(writer) })
|
||||
// A time that changes each observation, and a hash-shaped word: one line, quoting neither.
|
||||
for _, at := range []string{"23:32", "23:33", "23:34"} {
|
||||
if _, err := k.Observe(t.Context(), Observation{Scope: ScopeMachine, ID: "ace", Kind: "test-clock", Machine: "ace",
|
||||
Severity: Warning, Source: "test", Summary: "s", Headline: "ace was given a secret",
|
||||
Explanation: "It was given at 23:32.", Resolved: "Seen"}); err != nil {
|
||||
Explanation: "It was given at " + at + ".", Resolved: "Seen"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
}
|
||||
if got := out.String(); strings.Count(got, "\n") != 1 || !strings.Contains(got, `"test-clock"`) ||
|
||||
!strings.Contains(got, "a clock time or date") {
|
||||
if _, err := k.Observe(t.Context(), Observation{Scope: ScopeMachine, ID: "ace", Kind: "test-hash", Machine: "ace",
|
||||
Severity: Warning, Source: "test", Summary: "s", Headline: "ace was given 0123abcd4567ef89",
|
||||
Explanation: "It was given.", Resolved: "Seen"}); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if got := out.String(); strings.Count(got, "\n") != 2 || !strings.Contains(got, `"test-clock"`) ||
|
||||
!strings.Contains(got, "a clock time or date") || strings.Contains(got, "23:3") ||
|
||||
!strings.Contains(got, `"test-hash"`) || strings.Contains(got, "0123abcd4567ef89") {
|
||||
t.Errorf("the log said %q", got)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user