mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-11 01:36:37 +08:00
refactor(agent): stop embedding GeoIP MMDB in agent binary
Agent ships without City/Country MMDB in the binary; Docker images COPY databases into data_dir, bare installs seed via download on first start. Server keeps Country-only embed for optional MaxMind control-plane use. Also harden fetch script nonempty check and reject non-file MMDB paths.
This commit is contained in:
Binary file not shown.
|
Before Width: | Height: | Size: 63 MiB |
Binary file not shown.
@@ -1,16 +1,13 @@
|
||||
// Package geoipdata embeds the default MaxMind GeoLite2 databases.
|
||||
// Package geoipdata holds shared GeoIP database filename constants.
|
||||
//
|
||||
// MaxMind MMDB files are NOT embedded into the agent binary. Docker images
|
||||
// COPY them onto the default data paths; bare binary installs seed via download
|
||||
// on first start (see geoipupdate).
|
||||
package geoipdata
|
||||
|
||||
import "embed"
|
||||
|
||||
// FS holds the embedded GeoLite2 Country and City databases.
|
||||
//
|
||||
//go:embed GeoLite2-Country.mmdb GeoLite2-City.mmdb
|
||||
var FS embed.FS
|
||||
|
||||
const (
|
||||
// DefaultMMDBName is the filename of the embedded MaxMind Country database.
|
||||
// DefaultMMDBName is the default Country database filename.
|
||||
DefaultMMDBName = "GeoLite2-Country.mmdb"
|
||||
// DefaultCityMMDBName is the filename of the embedded MaxMind City database.
|
||||
// DefaultCityMMDBName is the default City database filename.
|
||||
DefaultCityMMDBName = "GeoLite2-City.mmdb"
|
||||
)
|
||||
|
||||
@@ -1,38 +0,0 @@
|
||||
package geoipdata
|
||||
|
||||
import (
|
||||
"io/fs"
|
||||
"strings"
|
||||
"testing"
|
||||
|
||||
"github.com/oschwald/maxminddb-golang"
|
||||
)
|
||||
|
||||
func TestEmbeddedDatabasesAreValid(t *testing.T) {
|
||||
tests := []struct {
|
||||
name string
|
||||
filename string
|
||||
databaseTypePart string
|
||||
}{
|
||||
{name: "Country", filename: DefaultMMDBName, databaseTypePart: "Country"},
|
||||
{name: "City", filename: DefaultCityMMDBName, databaseTypePart: "City"},
|
||||
}
|
||||
|
||||
for _, test := range tests {
|
||||
t.Run(test.name, func(t *testing.T) {
|
||||
data, err := fs.ReadFile(FS, test.filename)
|
||||
if err != nil {
|
||||
t.Fatalf("read embedded database: %v", err)
|
||||
}
|
||||
reader, err := maxminddb.FromBytes(data)
|
||||
if err != nil {
|
||||
t.Fatalf("open embedded database: %v", err)
|
||||
}
|
||||
defer reader.Close()
|
||||
|
||||
if !strings.Contains(reader.Metadata.DatabaseType, test.databaseTypePart) {
|
||||
t.Fatalf("unexpected database type %q", reader.Metadata.DatabaseType)
|
||||
}
|
||||
})
|
||||
}
|
||||
}
|
||||
@@ -5,23 +5,16 @@ import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"log/slog"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"time"
|
||||
|
||||
"github.com/Rain-kl/Wavelet/internal/apps/agent/geoipdata"
|
||||
"github.com/Rain-kl/Wavelet/pkg/geoip"
|
||||
)
|
||||
|
||||
const (
|
||||
mmdbDirPerm = 0o750
|
||||
mmdbFilePerm = 0o600
|
||||
)
|
||||
|
||||
// Updater periodically downloads a fresh GeoIP MMDB file and seeds the
|
||||
// initial embedded database when none is present on disk.
|
||||
// Updater periodically downloads a fresh GeoIP MMDB file and seeds missing
|
||||
// databases via download (or relies on image-provided files under data_dir).
|
||||
type Updater struct {
|
||||
MMDBPath string
|
||||
DownloadURL string
|
||||
@@ -31,48 +24,58 @@ type Updater struct {
|
||||
downloadDatabase func(context.Context, string, string) error
|
||||
}
|
||||
|
||||
// EnsureInitialDatabase seeds the Country MMDB file from the embedded database if it does not exist on disk.
|
||||
func (u *Updater) EnsureInitialDatabase() error {
|
||||
return ensureEmbeddedDatabase(u.MMDBPath, geoipdata.DefaultMMDBName, "Country")
|
||||
}
|
||||
|
||||
func ensureEmbeddedDatabase(targetPath string, embeddedName string, databaseName string) error {
|
||||
path := filepath.Clean(targetPath)
|
||||
if path == "" || path == "." {
|
||||
// EnsureInitialDatabases downloads any missing Country/City MMDB once.
|
||||
// When files already exist (e.g. Docker image COPY), this is a no-op.
|
||||
// Network is used only when a managed path is absent — not for binary embeds.
|
||||
func (u *Updater) EnsureInitialDatabases(ctx context.Context) error {
|
||||
if u == nil {
|
||||
return nil
|
||||
}
|
||||
if _, err := os.Stat(path); err == nil {
|
||||
return nil
|
||||
} else if !os.IsNotExist(err) {
|
||||
return fmt.Errorf("stat mmdb file failed: %w", err)
|
||||
}
|
||||
data, err := fs.ReadFile(geoipdata.FS, embeddedName)
|
||||
if err != nil {
|
||||
return fmt.Errorf("read embedded %s mmdb failed: %w", databaseName, err)
|
||||
}
|
||||
if err := os.MkdirAll(filepath.Dir(path), mmdbDirPerm); err != nil {
|
||||
return fmt.Errorf("create mmdb directory failed: %w", err)
|
||||
}
|
||||
if err := os.WriteFile(path, data, mmdbFilePerm); err != nil {
|
||||
return fmt.Errorf("write initial mmdb failed: %w", err)
|
||||
}
|
||||
slog.Info("initialized GeoIP mmdb from embedded database", "database", databaseName, "path", path, "size", len(data))
|
||||
return nil
|
||||
return u.ensureMissingDatabases(ctx)
|
||||
}
|
||||
|
||||
// EnsureInitialDatabases seeds both Country and City from embedded databases
|
||||
// when either managed file is absent. Network downloads are reserved for the periodic updater.
|
||||
func (u *Updater) EnsureInitialDatabases(_ context.Context) error {
|
||||
func (u *Updater) ensureMissingDatabases(ctx context.Context) error {
|
||||
databases := u.managedDatabases()
|
||||
var errs []error
|
||||
if err := u.EnsureInitialDatabase(); err != nil {
|
||||
errs = append(errs, err)
|
||||
}
|
||||
if err := ensureEmbeddedDatabase(u.CityMMDBPath, geoipdata.DefaultCityMMDBName, "City"); err != nil {
|
||||
errs = append(errs, err)
|
||||
for _, database := range databases {
|
||||
if database.path == "" || database.downloadURL == "" {
|
||||
continue
|
||||
}
|
||||
exists, err := fileExists(database.path)
|
||||
if err != nil {
|
||||
errs = append(errs, fmt.Errorf("stat GeoIP %s mmdb failed: %w", database.name, err))
|
||||
continue
|
||||
}
|
||||
if exists {
|
||||
continue
|
||||
}
|
||||
if err := u.download(ctx, database.path, database.downloadURL); err != nil {
|
||||
errs = append(errs, fmt.Errorf("seed GeoIP %s mmdb failed: %w", database.name, err))
|
||||
continue
|
||||
}
|
||||
slog.Info("seeded GeoIP mmdb via download", "database", database.name, "path", database.path)
|
||||
}
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
|
||||
func fileExists(path string) (bool, error) {
|
||||
path = filepath.Clean(path)
|
||||
if path == "" || path == "." {
|
||||
return false, nil
|
||||
}
|
||||
info, err := os.Stat(path)
|
||||
if err == nil {
|
||||
if !info.Mode().IsRegular() {
|
||||
return false, fmt.Errorf("GeoIP MMDB path is not a regular file: %s", path)
|
||||
}
|
||||
return true, nil
|
||||
}
|
||||
if os.IsNotExist(err) {
|
||||
return false, nil
|
||||
}
|
||||
return false, err
|
||||
}
|
||||
|
||||
func (u *Updater) download(ctx context.Context, path string, downloadURL string) error {
|
||||
if u.downloadDatabase != nil {
|
||||
return u.downloadDatabase(ctx, path, downloadURL)
|
||||
@@ -80,8 +83,12 @@ func (u *Updater) download(ctx context.Context, path string, downloadURL string)
|
||||
return geoip.DownloadMaxMindDatabase(ctx, path, downloadURL)
|
||||
}
|
||||
|
||||
func (u *Updater) updateDatabases(ctx context.Context) error {
|
||||
databases := []struct {
|
||||
func (u *Updater) managedDatabases() []struct {
|
||||
name string
|
||||
path string
|
||||
downloadURL string
|
||||
} {
|
||||
return []struct {
|
||||
name string
|
||||
path string
|
||||
downloadURL string
|
||||
@@ -89,9 +96,12 @@ func (u *Updater) updateDatabases(ctx context.Context) error {
|
||||
{name: "Country", path: u.MMDBPath, downloadURL: u.DownloadURL},
|
||||
{name: "City", path: u.CityMMDBPath, downloadURL: u.CityDownloadURL},
|
||||
}
|
||||
}
|
||||
|
||||
func (u *Updater) updateDatabases(ctx context.Context) error {
|
||||
var errs []error
|
||||
for _, database := range databases {
|
||||
if database.path == "" || (database.name == "City" && database.downloadURL == "") {
|
||||
for _, database := range u.managedDatabases() {
|
||||
if database.path == "" || database.downloadURL == "" {
|
||||
continue
|
||||
}
|
||||
if err := u.download(ctx, database.path, database.downloadURL); err != nil {
|
||||
|
||||
@@ -6,77 +6,66 @@ import (
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
"strings"
|
||||
"testing"
|
||||
)
|
||||
|
||||
func TestEnsureInitialDatabaseCopiesEmbeddedMMDB(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
path := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
updater := &Updater{MMDBPath: path}
|
||||
|
||||
if err := updater.EnsureInitialDatabase(); err != nil {
|
||||
t.Fatalf("EnsureInitialDatabase failed: %v", err)
|
||||
}
|
||||
info, err := os.Stat(path)
|
||||
if err != nil {
|
||||
t.Fatalf("expected mmdb to exist: %v", err)
|
||||
}
|
||||
if info.Size() == 0 {
|
||||
t.Fatal("expected copied mmdb to be non-empty")
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesCopiesEmbeddedCityWithoutDownload(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
|
||||
updater := &Updater{
|
||||
MMDBPath: countryPath,
|
||||
CityMMDBPath: cityPath,
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, path, downloadURL string) error {
|
||||
t.Fatalf("initial embedded seed must not download %s from %s", path, downloadURL)
|
||||
return nil
|
||||
},
|
||||
}
|
||||
|
||||
if err := updater.EnsureInitialDatabases(context.Background()); err != nil {
|
||||
t.Fatalf("EnsureInitialDatabases failed: %v", err)
|
||||
}
|
||||
if _, err := os.Stat(countryPath); err != nil {
|
||||
t.Fatalf("expected embedded Country database: %v", err)
|
||||
}
|
||||
data, err := os.ReadFile(cityPath)
|
||||
if err != nil || len(data) == 0 {
|
||||
t.Fatalf("expected embedded City database, size=%d err=%v", len(data), err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesKeepsExistingCityWithoutDownload(t *testing.T) {
|
||||
func TestEnsureInitialDatabasesDownloadsMissingOnly(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
|
||||
if err := os.WriteFile(cityPath, []byte("existing-city"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
|
||||
var downloaded []string
|
||||
updater := &Updater{
|
||||
MMDBPath: countryPath,
|
||||
DownloadURL: "https://geo.example/GeoLite2-Country.mmdb",
|
||||
CityMMDBPath: cityPath,
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, _, _ string) error {
|
||||
return errors.New("city unavailable")
|
||||
downloadDatabase: func(_ context.Context, path, _ string) error {
|
||||
downloaded = append(downloaded, path)
|
||||
return os.WriteFile(path, []byte("downloaded"), 0o600)
|
||||
},
|
||||
}
|
||||
|
||||
if err := updater.EnsureInitialDatabases(context.Background()); err != nil {
|
||||
t.Fatalf("EnsureInitialDatabases failed: %v", err)
|
||||
}
|
||||
if _, err := os.Stat(countryPath); err != nil {
|
||||
t.Fatalf("expected Country fallback to remain available: %v", err)
|
||||
if !slices.Equal(downloaded, []string{countryPath}) {
|
||||
t.Fatalf("expected only missing Country download, got %#v", downloaded)
|
||||
}
|
||||
data, err := os.ReadFile(cityPath)
|
||||
if err != nil || string(data) != "existing-city" {
|
||||
t.Fatalf("expected existing City database to remain untouched, data=%q err=%v", data, err)
|
||||
if data, err := os.ReadFile(cityPath); err != nil || string(data) != "existing-city" {
|
||||
t.Fatalf("existing City must stay untouched, data=%q err=%v", data, err)
|
||||
}
|
||||
if data, err := os.ReadFile(countryPath); err != nil || string(data) != "downloaded" {
|
||||
t.Fatalf("Country should be seeded via download, data=%q err=%v", data, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesNoOpWhenPresent(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
|
||||
if err := os.WriteFile(countryPath, []byte("c"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
if err := os.WriteFile(cityPath, []byte("city"), 0o600); err != nil {
|
||||
t.Fatal(err)
|
||||
}
|
||||
updater := &Updater{
|
||||
MMDBPath: countryPath,
|
||||
DownloadURL: "https://geo.example/GeoLite2-Country.mmdb",
|
||||
CityMMDBPath: cityPath,
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, path, downloadURL string) error {
|
||||
t.Fatalf("must not download when files exist: %s %s", path, downloadURL)
|
||||
return nil
|
||||
},
|
||||
}
|
||||
if err := updater.EnsureInitialDatabases(context.Background()); err != nil {
|
||||
t.Fatalf("EnsureInitialDatabases failed: %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
@@ -101,3 +90,24 @@ func TestUpdateDatabasesAttemptsCityAfterCountryFailure(t *testing.T) {
|
||||
t.Fatalf("expected independent Country then City attempts, paths=%#v err=%v", paths, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesRejectsDirectoryPath(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
// Point Country path at a directory so fileExists must not treat it as seeded.
|
||||
updater := &Updater{
|
||||
MMDBPath: tempDir,
|
||||
DownloadURL: "https://geo.example/GeoLite2-Country.mmdb",
|
||||
downloadDatabase: func(_ context.Context, path, downloadURL string) error {
|
||||
t.Fatalf("must not download when path is a directory: %s %s", path, downloadURL)
|
||||
return nil
|
||||
},
|
||||
}
|
||||
|
||||
err := updater.EnsureInitialDatabases(context.Background())
|
||||
if err == nil {
|
||||
t.Fatal("expected error when MMDB path is a directory")
|
||||
}
|
||||
if !strings.Contains(err.Error(), "not a regular file") {
|
||||
t.Fatalf("expected regular-file error, got %v", err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user