Apps break on hosts where Splunk is configured to listen on IPv6 management port

未关闭
#334 6 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

评估

难度
2/5
预计耗时
1-3 小时
新手友好度
45/100
Issue 类型
缺陷
描述清晰度
基本清楚
活跃度
停滞
技术栈
python
领域
backend

调研方向

Start in solnlib/splunkenv.py around get_splunkd_access_info(), especially the parsing of mgmtHostPort returned by get_conf_key_value(). Reproduce the failure with an IPv6 value such as [::]:8089 and verify that the management port is parsed correctly without breaking existing host:port values. The issue does not mention a specific test file, so add or locate coverage for these configurations before confirming the fix.

由索引模型根据 Issue 内容生成。

描述

For apps which invoke the get_splunkd_access_info() function from splunkenv.py, errors are thrown when a host is configured to listen using IPv6 on the Splunk MGMT port.

This function uses get_conf_key_value() to read the value of mgmtHostPort from web.conf, and splits it based on the : delimiter in order to work out the value being used for the MGMT port on the current instance:

https://github.com/splunk/addonfactory-solutions-library-python/blob/ed4749fa4cca8caabd3cc90ddd56b4a19824751d/solnlib/splunkenv.py#L187-L191

This obviously breaks when encountering IPv6 addresses, which use : as a delimiter as part of the address. This also breaks when deploying a Splunk-recommended configuration to listen on IPv6 as well as v4, which looks like this:

mgmtHostPort = [::]:8089

This type of construct is interestingly not included in the spec file for web.conf but in the spec file for server.conf, which states:

You might need to change the mgmtHostPort setting in the web.conf file. Use '[::1]' instead of '127.0.0.1'.

I'm not quite sure what the best way of fixing this is. It seems like using : as a delimiter should still be possible, but the function should take care to ensure that where multiple : delimiters are present, the rightmost value is taken as the integer used for the port value.

An example error from a Splunkbase app breaking because of this bug:

12-11-2023 17:07:25.671 +0000 ERROR AdminManagerExternal [109547 TcpChannelThread] - Stack trace from python handler:\nTraceback (most recent call last):\n  File "/opt/splunk/lib/python3.7/site-packages/splunk/admin.py", line 108, in init_persistent\n    hand = handler(mode, ctxInfo, data)\n  File "/opt/splunk/etc/apps/TA-sandfly-security/bin/ta_sandfly_security/aob_py3/splunktaucclib/rest_handler/admin_external.py", line 95, in __init__\n    get_splunkd_endpoint(),\n  File "/opt/splunk/etc/apps/TA-sandfly-security/bin/ta_sandfly_security/aob_py3/splunktaucclib/rest_handler/admin_external.py", line 77, in get_splunkd_endpoint\n    splunkd_uri = get_splunkd_uri()\n  File "/opt/splunk/etc/apps/TA-sandfly-security/bin/ta_sandfly_security/aob_py3/solnlib/splunkenv.py", line 208, in get_splunkd_uri\n    scheme, host, port = get_splunkd_access_info()\n  File "/opt/splunk/etc/apps/TA-sandfly-security/bin/ta_sandfly_security/aob_py3/solnlib/splunkenv.py", line 188, in get_splunkd_access_info\n    port = int(host_port.split(":")[1])\nValueError: invalid literal for int() with base 10: ''\n
主要语言
Python
星标
18
派生
10
PR 合并指标
30 天内没有已合并 PR

贡献指南

这个仓库没有索引到贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

splunk/addonfactory-solutions-library-python 的其他 Issue

查看 splunk/addonfactory-solutions-library-python 的全部 Issue

相似的 Issue

更多 Python Issue

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。