feat(waf): complete composable rule orchestration

Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
This commit is contained in:
ryan
2026-07-13 14:16:55 +08:00
parent d36409fbf9
commit a1a997bcda
72 changed files with 5897 additions and 3080 deletions
+66 -9
View File
@@ -3,6 +3,7 @@ package geoipupdate
import (
"context"
"errors"
"fmt"
"io/fs"
"log/slog"
@@ -22,9 +23,12 @@ const (
// Updater periodically downloads a fresh GeoIP MMDB file and seeds the
// initial embedded database when none is present on disk.
type Updater struct {
MMDBPath string
DownloadURL string
UpdateInterval time.Duration
MMDBPath string
DownloadURL string
CityMMDBPath string
CityDownloadURL string
UpdateInterval time.Duration
downloadDatabase func(context.Context, string, string) error
}
// EnsureInitialDatabase seeds the MMDB file from the embedded database if it does not exist on disk.
@@ -52,13 +56,68 @@ func (u *Updater) EnsureInitialDatabase() error {
return nil
}
// EnsureInitialDatabases retains the embedded Country seed and immediately
// downloads City when it is absent so subdivision rules work before the first ticker interval.
func (u *Updater) EnsureInitialDatabases(ctx context.Context) error {
var errs []error
if err := u.EnsureInitialDatabase(); err != nil {
errs = append(errs, err)
}
cityPath := filepath.Clean(u.CityMMDBPath)
if cityPath == "" || cityPath == "." || u.CityDownloadURL == "" {
return errors.Join(errs...)
}
if _, err := os.Stat(cityPath); err == nil {
return errors.Join(errs...)
} else if !os.IsNotExist(err) {
errs = append(errs, fmt.Errorf("stat City mmdb file failed: %w", err))
return errors.Join(errs...)
}
if err := u.download(ctx, cityPath, u.CityDownloadURL); err != nil {
errs = append(errs, fmt.Errorf("download initial City mmdb failed: %w", err))
} else {
slog.Info("initialized GeoIP City mmdb from provider", "path", cityPath)
}
return errors.Join(errs...)
}
func (u *Updater) download(ctx context.Context, path string, downloadURL string) error {
if u.downloadDatabase != nil {
return u.downloadDatabase(ctx, path, downloadURL)
}
return geoip.DownloadMaxMindDatabase(ctx, path, downloadURL)
}
func (u *Updater) updateDatabases(ctx context.Context) error {
databases := []struct {
name string
path string
downloadURL string
}{
{name: "Country", path: u.MMDBPath, downloadURL: u.DownloadURL},
{name: "City", path: u.CityMMDBPath, downloadURL: u.CityDownloadURL},
}
var errs []error
for _, database := range databases {
if database.path == "" || (database.name == "City" && database.downloadURL == "") {
continue
}
if err := u.download(ctx, database.path, database.downloadURL); err != nil {
errs = append(errs, fmt.Errorf("update GeoIP %s mmdb failed: %w", database.name, err))
continue
}
slog.Info("GeoIP mmdb updated", "database", database.name, "path", database.path)
}
return errors.Join(errs...)
}
// Run starts the periodic GeoIP update loop and blocks until ctx is cancelled.
func (u *Updater) Run(ctx context.Context) {
if u == nil || u.MMDBPath == "" || u.UpdateInterval <= 0 {
return
}
if err := u.EnsureInitialDatabase(); err != nil {
slog.Warn("initialize GeoIP mmdb failed", "path", u.MMDBPath, "error", err)
if err := u.EnsureInitialDatabases(ctx); err != nil {
slog.Warn("initialize GeoIP databases failed", "country_path", u.MMDBPath, "city_path", u.CityMMDBPath, "error", err)
}
ticker := time.NewTicker(u.UpdateInterval)
defer ticker.Stop()
@@ -67,11 +126,9 @@ func (u *Updater) Run(ctx context.Context) {
case <-ctx.Done():
return
case <-ticker.C:
if err := geoip.DownloadMaxMindDatabase(ctx, u.MMDBPath, u.DownloadURL); err != nil {
slog.Warn("update GeoIP mmdb failed", "path", u.MMDBPath, "error", err)
continue
if err := u.updateDatabases(ctx); err != nil {
slog.Warn("update GeoIP databases failed", "error", err)
}
slog.Info("GeoIP mmdb updated", "path", u.MMDBPath)
}
}
}
@@ -1,8 +1,11 @@
package geoipupdate
import (
"context"
"errors"
"os"
"path/filepath"
"slices"
"testing"
)
@@ -22,3 +25,77 @@ func TestEnsureInitialDatabaseCopiesEmbeddedMMDB(t *testing.T) {
t.Fatal("expected copied mmdb to be non-empty")
}
}
func TestEnsureInitialDatabasesDownloadsMissingCity(t *testing.T) {
tempDir := t.TempDir()
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
updater := &Updater{
MMDBPath: countryPath,
CityMMDBPath: cityPath,
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
downloadDatabase: func(_ context.Context, path, downloadURL string) error {
if path != cityPath || downloadURL != "https://geo.example/GeoLite2-City.mmdb" {
t.Fatalf("unexpected initial download: %s / %s", path, downloadURL)
}
return os.WriteFile(path, []byte("city-mmdb"), 0o600)
},
}
if err := updater.EnsureInitialDatabases(context.Background()); err != nil {
t.Fatalf("EnsureInitialDatabases failed: %v", err)
}
if _, err := os.Stat(countryPath); err != nil {
t.Fatalf("expected embedded Country database: %v", err)
}
data, err := os.ReadFile(cityPath)
if err != nil || string(data) != "city-mmdb" {
t.Fatalf("expected downloaded City database, data=%q err=%v", data, err)
}
}
func TestEnsureInitialDatabasesKeepsCountryFallbackWhenCityDownloadFails(t *testing.T) {
tempDir := t.TempDir()
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
updater := &Updater{
MMDBPath: countryPath,
CityMMDBPath: cityPath,
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
downloadDatabase: func(_ context.Context, _, _ string) error {
return errors.New("city unavailable")
},
}
if err := updater.EnsureInitialDatabases(context.Background()); err == nil {
t.Fatal("expected City download error to be reported")
}
if _, err := os.Stat(countryPath); err != nil {
t.Fatalf("expected Country fallback to remain available: %v", err)
}
if _, err := os.Stat(cityPath); !errors.Is(err, os.ErrNotExist) {
t.Fatalf("expected failed City download not to create a database, err=%v", err)
}
}
func TestUpdateDatabasesAttemptsCityAfterCountryFailure(t *testing.T) {
var paths []string
updater := &Updater{
MMDBPath: "/data/GeoLite2-Country.mmdb",
DownloadURL: "https://geo.example/GeoLite2-Country.mmdb",
CityMMDBPath: "/data/GeoLite2-City.mmdb",
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
downloadDatabase: func(_ context.Context, path, _ string) error {
paths = append(paths, path)
if path == "/data/GeoLite2-Country.mmdb" {
return errors.New("country unavailable")
}
return nil
},
}
err := updater.updateDatabases(context.Background())
if err == nil || !slices.Equal(paths, []string{"/data/GeoLite2-Country.mmdb", "/data/GeoLite2-City.mmdb"}) {
t.Fatalf("expected independent Country then City attempts, paths=%#v err=%v", paths, err)
}
}