[MM-48825] "plugin configured with a nil SecureConfig" warning logged when starting each plugin (#21869)
Этот коммит содержится в:
коммит произвёл
GitHub
родитель
7bfca605e1
Коммит
f852237e33
@@ -4,7 +4,10 @@
|
|||||||
package plugin
|
package plugin
|
||||||
|
|
||||||
import (
|
import (
|
||||||
|
"crypto/sha256"
|
||||||
"fmt"
|
"fmt"
|
||||||
|
"io"
|
||||||
|
"os"
|
||||||
"os/exec"
|
"os/exec"
|
||||||
"path/filepath"
|
"path/filepath"
|
||||||
"runtime"
|
"runtime"
|
||||||
@@ -62,6 +65,14 @@ func newSupervisor(pluginInfo *model.BundleInfo, apiImpl API, driver Driver, par
|
|||||||
|
|
||||||
cmd := exec.Command(executable)
|
cmd := exec.Command(executable)
|
||||||
|
|
||||||
|
// This doesn't add more security than before
|
||||||
|
// but removes the SecureConfig is nil warning.
|
||||||
|
// https://mattermost.atlassian.net/browse/MM-49167
|
||||||
|
pluginChecksum, err := getPluginExecutableChecksum(executable)
|
||||||
|
if err != nil {
|
||||||
|
return nil, fmt.Errorf("unable to generate a checksum for the plugin %s", pluginInfo.Path)
|
||||||
|
}
|
||||||
|
|
||||||
sup.client = plugin.NewClient(&plugin.ClientConfig{
|
sup.client = plugin.NewClient(&plugin.ClientConfig{
|
||||||
HandshakeConfig: handshake,
|
HandshakeConfig: handshake,
|
||||||
Plugins: pluginMap,
|
Plugins: pluginMap,
|
||||||
@@ -70,6 +81,10 @@ func newSupervisor(pluginInfo *model.BundleInfo, apiImpl API, driver Driver, par
|
|||||||
SyncStderr: wrappedLogger.With(mlog.String("source", "plugin_stderr")).StdLogWriter(),
|
SyncStderr: wrappedLogger.With(mlog.String("source", "plugin_stderr")).StdLogWriter(),
|
||||||
Logger: hclogAdaptedLogger,
|
Logger: hclogAdaptedLogger,
|
||||||
StartTimeout: time.Second * 3,
|
StartTimeout: time.Second * 3,
|
||||||
|
SecureConfig: &plugin.SecureConfig{
|
||||||
|
Checksum: pluginChecksum,
|
||||||
|
Hash: sha256.New(),
|
||||||
|
},
|
||||||
})
|
})
|
||||||
|
|
||||||
rpcClient, err := sup.client.Client()
|
rpcClient, err := sup.client.Client()
|
||||||
@@ -158,3 +173,21 @@ func (sup *supervisor) Implements(hookId int) bool {
|
|||||||
defer sup.lock.RUnlock()
|
defer sup.lock.RUnlock()
|
||||||
return sup.implemented[hookId]
|
return sup.implemented[hookId]
|
||||||
}
|
}
|
||||||
|
|
||||||
|
func getPluginExecutableChecksum(executablePath string) ([]byte, error) {
|
||||||
|
pathHash := sha256.New()
|
||||||
|
file, err := os.Open(executablePath)
|
||||||
|
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
defer file.Close()
|
||||||
|
|
||||||
|
_, err = io.Copy(pathHash, file)
|
||||||
|
if err != nil {
|
||||||
|
return nil, err
|
||||||
|
}
|
||||||
|
|
||||||
|
return pathHash.Sum(nil), nil
|
||||||
|
}
|
||||||
|
|||||||
Ссылка в новой задаче
Block a user