mirror of
https://github.com/Rain-kl/OpenFlare.git
synced 2026-10-07 08:06:37 +08:00
feat(waf): complete composable rule orchestration
Add the React Flow rule editor, ordered graph APIs and runtime DAG execution.\n\nPublish rules only on OpenResty reload and reconcile checksum-driven IP group snapshots in bounded shared memory.
This commit is contained in:
@@ -3,6 +3,7 @@ package geoipupdate
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"fmt"
|
||||
"io/fs"
|
||||
"log/slog"
|
||||
@@ -22,9 +23,12 @@ const (
|
||||
// Updater periodically downloads a fresh GeoIP MMDB file and seeds the
|
||||
// initial embedded database when none is present on disk.
|
||||
type Updater struct {
|
||||
MMDBPath string
|
||||
DownloadURL string
|
||||
UpdateInterval time.Duration
|
||||
MMDBPath string
|
||||
DownloadURL string
|
||||
CityMMDBPath string
|
||||
CityDownloadURL string
|
||||
UpdateInterval time.Duration
|
||||
downloadDatabase func(context.Context, string, string) error
|
||||
}
|
||||
|
||||
// EnsureInitialDatabase seeds the MMDB file from the embedded database if it does not exist on disk.
|
||||
@@ -52,13 +56,68 @@ func (u *Updater) EnsureInitialDatabase() error {
|
||||
return nil
|
||||
}
|
||||
|
||||
// EnsureInitialDatabases retains the embedded Country seed and immediately
|
||||
// downloads City when it is absent so subdivision rules work before the first ticker interval.
|
||||
func (u *Updater) EnsureInitialDatabases(ctx context.Context) error {
|
||||
var errs []error
|
||||
if err := u.EnsureInitialDatabase(); err != nil {
|
||||
errs = append(errs, err)
|
||||
}
|
||||
cityPath := filepath.Clean(u.CityMMDBPath)
|
||||
if cityPath == "" || cityPath == "." || u.CityDownloadURL == "" {
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
if _, err := os.Stat(cityPath); err == nil {
|
||||
return errors.Join(errs...)
|
||||
} else if !os.IsNotExist(err) {
|
||||
errs = append(errs, fmt.Errorf("stat City mmdb file failed: %w", err))
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
if err := u.download(ctx, cityPath, u.CityDownloadURL); err != nil {
|
||||
errs = append(errs, fmt.Errorf("download initial City mmdb failed: %w", err))
|
||||
} else {
|
||||
slog.Info("initialized GeoIP City mmdb from provider", "path", cityPath)
|
||||
}
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
|
||||
func (u *Updater) download(ctx context.Context, path string, downloadURL string) error {
|
||||
if u.downloadDatabase != nil {
|
||||
return u.downloadDatabase(ctx, path, downloadURL)
|
||||
}
|
||||
return geoip.DownloadMaxMindDatabase(ctx, path, downloadURL)
|
||||
}
|
||||
|
||||
func (u *Updater) updateDatabases(ctx context.Context) error {
|
||||
databases := []struct {
|
||||
name string
|
||||
path string
|
||||
downloadURL string
|
||||
}{
|
||||
{name: "Country", path: u.MMDBPath, downloadURL: u.DownloadURL},
|
||||
{name: "City", path: u.CityMMDBPath, downloadURL: u.CityDownloadURL},
|
||||
}
|
||||
var errs []error
|
||||
for _, database := range databases {
|
||||
if database.path == "" || (database.name == "City" && database.downloadURL == "") {
|
||||
continue
|
||||
}
|
||||
if err := u.download(ctx, database.path, database.downloadURL); err != nil {
|
||||
errs = append(errs, fmt.Errorf("update GeoIP %s mmdb failed: %w", database.name, err))
|
||||
continue
|
||||
}
|
||||
slog.Info("GeoIP mmdb updated", "database", database.name, "path", database.path)
|
||||
}
|
||||
return errors.Join(errs...)
|
||||
}
|
||||
|
||||
// Run starts the periodic GeoIP update loop and blocks until ctx is cancelled.
|
||||
func (u *Updater) Run(ctx context.Context) {
|
||||
if u == nil || u.MMDBPath == "" || u.UpdateInterval <= 0 {
|
||||
return
|
||||
}
|
||||
if err := u.EnsureInitialDatabase(); err != nil {
|
||||
slog.Warn("initialize GeoIP mmdb failed", "path", u.MMDBPath, "error", err)
|
||||
if err := u.EnsureInitialDatabases(ctx); err != nil {
|
||||
slog.Warn("initialize GeoIP databases failed", "country_path", u.MMDBPath, "city_path", u.CityMMDBPath, "error", err)
|
||||
}
|
||||
ticker := time.NewTicker(u.UpdateInterval)
|
||||
defer ticker.Stop()
|
||||
@@ -67,11 +126,9 @@ func (u *Updater) Run(ctx context.Context) {
|
||||
case <-ctx.Done():
|
||||
return
|
||||
case <-ticker.C:
|
||||
if err := geoip.DownloadMaxMindDatabase(ctx, u.MMDBPath, u.DownloadURL); err != nil {
|
||||
slog.Warn("update GeoIP mmdb failed", "path", u.MMDBPath, "error", err)
|
||||
continue
|
||||
if err := u.updateDatabases(ctx); err != nil {
|
||||
slog.Warn("update GeoIP databases failed", "error", err)
|
||||
}
|
||||
slog.Info("GeoIP mmdb updated", "path", u.MMDBPath)
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
@@ -1,8 +1,11 @@
|
||||
package geoipupdate
|
||||
|
||||
import (
|
||||
"context"
|
||||
"errors"
|
||||
"os"
|
||||
"path/filepath"
|
||||
"slices"
|
||||
"testing"
|
||||
)
|
||||
|
||||
@@ -22,3 +25,77 @@ func TestEnsureInitialDatabaseCopiesEmbeddedMMDB(t *testing.T) {
|
||||
t.Fatal("expected copied mmdb to be non-empty")
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesDownloadsMissingCity(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
|
||||
updater := &Updater{
|
||||
MMDBPath: countryPath,
|
||||
CityMMDBPath: cityPath,
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, path, downloadURL string) error {
|
||||
if path != cityPath || downloadURL != "https://geo.example/GeoLite2-City.mmdb" {
|
||||
t.Fatalf("unexpected initial download: %s / %s", path, downloadURL)
|
||||
}
|
||||
return os.WriteFile(path, []byte("city-mmdb"), 0o600)
|
||||
},
|
||||
}
|
||||
|
||||
if err := updater.EnsureInitialDatabases(context.Background()); err != nil {
|
||||
t.Fatalf("EnsureInitialDatabases failed: %v", err)
|
||||
}
|
||||
if _, err := os.Stat(countryPath); err != nil {
|
||||
t.Fatalf("expected embedded Country database: %v", err)
|
||||
}
|
||||
data, err := os.ReadFile(cityPath)
|
||||
if err != nil || string(data) != "city-mmdb" {
|
||||
t.Fatalf("expected downloaded City database, data=%q err=%v", data, err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestEnsureInitialDatabasesKeepsCountryFallbackWhenCityDownloadFails(t *testing.T) {
|
||||
tempDir := t.TempDir()
|
||||
countryPath := filepath.Join(tempDir, "GeoLite2-Country.mmdb")
|
||||
cityPath := filepath.Join(tempDir, "GeoLite2-City.mmdb")
|
||||
updater := &Updater{
|
||||
MMDBPath: countryPath,
|
||||
CityMMDBPath: cityPath,
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, _, _ string) error {
|
||||
return errors.New("city unavailable")
|
||||
},
|
||||
}
|
||||
|
||||
if err := updater.EnsureInitialDatabases(context.Background()); err == nil {
|
||||
t.Fatal("expected City download error to be reported")
|
||||
}
|
||||
if _, err := os.Stat(countryPath); err != nil {
|
||||
t.Fatalf("expected Country fallback to remain available: %v", err)
|
||||
}
|
||||
if _, err := os.Stat(cityPath); !errors.Is(err, os.ErrNotExist) {
|
||||
t.Fatalf("expected failed City download not to create a database, err=%v", err)
|
||||
}
|
||||
}
|
||||
|
||||
func TestUpdateDatabasesAttemptsCityAfterCountryFailure(t *testing.T) {
|
||||
var paths []string
|
||||
updater := &Updater{
|
||||
MMDBPath: "/data/GeoLite2-Country.mmdb",
|
||||
DownloadURL: "https://geo.example/GeoLite2-Country.mmdb",
|
||||
CityMMDBPath: "/data/GeoLite2-City.mmdb",
|
||||
CityDownloadURL: "https://geo.example/GeoLite2-City.mmdb",
|
||||
downloadDatabase: func(_ context.Context, path, _ string) error {
|
||||
paths = append(paths, path)
|
||||
if path == "/data/GeoLite2-Country.mmdb" {
|
||||
return errors.New("country unavailable")
|
||||
}
|
||||
return nil
|
||||
},
|
||||
}
|
||||
|
||||
err := updater.updateDatabases(context.Background())
|
||||
if err == nil || !slices.Equal(paths, []string{"/data/GeoLite2-Country.mmdb", "/data/GeoLite2-City.mmdb"}) {
|
||||
t.Fatalf("expected independent Country then City attempts, paths=%#v err=%v", paths, err)
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user