* Add macsuck worker to collect various PortAccessEntity (NAC) attributes * Incorporate PAE feedback on #937 * missing Result/Device.pm column added * pae_is... columns instead of pae_capabilities * moved most code to Util/PortAccessEntity.pm so the update can be done in discover and macsuck * Refactor PAE attributes during discover as separate Plugin * PortAccessEntity: don't use device->dns in log string * Fix "Experimental keys on scalar is now forbidden" test failure * Revamp pae_control and add missing attribute - device.pae_control (text) is now device.pae_is_enabled (bool) - also store pae_authconfig_port_control (port mode auto/force(un)Auth) * Fix "Experimental keys on scalar is now forbidden" test failure - ... again because of botched merge - at least perlgolfed away a set of curly braces * Update PortAccessEntity.pm * Incorporate @ollyg PR feedback * allow actions without transport to run when there are also no creds * initial refactor for separate gather, process, store phases for macsuck * factor out the vlan sanity check * additional help with log of action workers * cleanup logic in check macsuck * refactor to make main phases only * some fixes * implement file slurp. amazingly the whole thing works * remove outdated noop from test * treat error as critical, use cancel to suppress further drivers * big refactor to share mac sanity code to both paths * fix inverted logic on vlan sanity filter * some code tidy * fix error in default value * fix for vlan 0 nodes input from cli * ensure imported MACs are IEEE format * add api endpoint, no useful return status yet * exit status if error from nodes PUT * suppress other networked workers when direct workers are active * better log showing worker * fix status recording to get first error or last done message * implement arpnip API PUT * avoid package redeclaration error * make sure write API methods require admin status * add doc for passing JSON data to arpnip and macsuck * update manifest * remove option to do jobs in web handler; all by queue now * use job entry timestamp for offline queued jobs * fix store username and IP on api PUT * never de-duplicate user-submitted jobs; never reset DeviceSkip for offline jobs * myworker no longer needed * make logic cleaner Co-authored-by: Christian Ramseyer <ramseyer@netnea.com>
112 lines
3.2 KiB
Perl
112 lines
3.2 KiB
Perl
package App::Netdisco::Worker::Runner;
|
|
|
|
use Dancer qw/:moose :syntax/;
|
|
use Dancer::Plugin::DBIC 'schema';
|
|
use App::Netdisco::Util::Device 'get_device';
|
|
use App::Netdisco::Util::Permission qw/check_acl_no check_acl_only/;
|
|
use aliased 'App::Netdisco::Worker::Status';
|
|
|
|
use Try::Tiny;
|
|
use Time::HiRes ();
|
|
use Module::Load ();
|
|
use Scope::Guard 'guard';
|
|
use Storable 'dclone';
|
|
use Sys::SigAction 'timeout_call';
|
|
|
|
use Moo::Role;
|
|
use namespace::clean;
|
|
|
|
with 'App::Netdisco::Worker::Loader';
|
|
has 'job' => ( is => 'rw' );
|
|
|
|
# mixin code to run workers loaded via plugins
|
|
sub run {
|
|
my ($self, $job) = @_;
|
|
|
|
die 'cannot reuse a worker' if $self->job;
|
|
die 'bad job to run()'
|
|
unless ref $job eq 'App::Netdisco::Backend::Job';
|
|
|
|
$self->job($job);
|
|
$job->device( get_device($job->device) );
|
|
$self->load_workers();
|
|
|
|
# finalise job status when we exit
|
|
my $statusguard = guard { $job->finalise_status };
|
|
|
|
my @newuserconf = ();
|
|
my @userconf = @{ dclone (setting('device_auth') || []) };
|
|
|
|
# reduce device_auth by only/no
|
|
if (ref $job->device) {
|
|
foreach my $stanza (@userconf) {
|
|
my $no = (exists $stanza->{no} ? $stanza->{no} : undef);
|
|
my $only = (exists $stanza->{only} ? $stanza->{only} : undef);
|
|
|
|
next if $no and check_acl_no($job->device, $no);
|
|
next if $only and not check_acl_only($job->device, $only);
|
|
|
|
push @newuserconf, dclone $stanza;
|
|
}
|
|
|
|
# per-device action but no device creds available
|
|
return $job->add_status( Status->defer('deferred job with no device creds') )
|
|
if 0 == scalar @newuserconf && $self->transport_required;
|
|
}
|
|
|
|
# back up and restore device_auth
|
|
my $configguard = guard { set(device_auth => \@userconf) };
|
|
set(device_auth => \@newuserconf);
|
|
|
|
my $runner = sub {
|
|
my ($self, $job) = @_;
|
|
# roll everything back if we're testing
|
|
my $txn_guard = $ENV{ND2_DB_ROLLBACK}
|
|
? schema('netdisco')->storage->txn_scope_guard : undef;
|
|
|
|
# run check phase and if there are workers then one MUST be successful
|
|
$self->run_workers('workers_check');
|
|
|
|
# run other phases
|
|
if ($job->check_passed) {
|
|
$self->run_workers("workers_${_}") for qw/early main user store late/;
|
|
}
|
|
};
|
|
|
|
my $maxtime = ((defined setting($job->action .'_timeout'))
|
|
? setting($job->action .'_timeout') : setting('workers')->{'timeout'});
|
|
if ($maxtime) {
|
|
debug sprintf '%s: running with timeout %ss', $job->action, $maxtime;
|
|
if (timeout_call($maxtime, $runner, ($self, $job))) {
|
|
debug sprintf '%s: timed out!', $job->action;
|
|
$job->add_status( Status->error("job timed out after $maxtime sec") );
|
|
}
|
|
}
|
|
else {
|
|
debug sprintf '%s: running with no timeout', $job->action;
|
|
$runner->($self, $job);
|
|
}
|
|
}
|
|
|
|
sub run_workers {
|
|
my $self = shift;
|
|
my $job = $self->job or die error 'no job in worker job slot';
|
|
|
|
my $set = shift
|
|
or return $job->add_status( Status->error('missing set param') );
|
|
return unless ref [] eq ref $self->$set and 0 < scalar @{ $self->$set };
|
|
|
|
(my $phase = $set) =~ s/^workers_//;
|
|
$job->enter_phase($phase);
|
|
|
|
foreach my $worker (@{ $self->$set }) {
|
|
try { $job->add_status( $worker->($job) ) }
|
|
catch {
|
|
debug "-> $_" if $_;
|
|
$job->add_status( Status->error($_) );
|
|
};
|
|
}
|
|
}
|
|
|
|
true;
|