Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
7 changes: 5 additions & 2 deletions internal/cmds/cmds.go
Original file line number Diff line number Diff line change
Expand Up @@ -223,9 +223,12 @@ func enable(ctx *log.Context, h types.HandlerEnvironment, report *types.RunComma
if _, err := os.Stat(policyPath); err == nil {
extensionPolicyManagerPtr, rceps, err, exitCode = extensionpolicysettingsrc.InitializeExtensionPolicySettings(ctx, policyPath)
if err != nil {
return "", "", err, exitCode
// TODO: In the future, fail the command if the policy file was invalid and return the exitCode.
// For now, log the error and continue with the command execution.
ctx.Log("error", "failed to initialize extension policy settings. Executing command with no policy applied for now.", "error", err, "errorCode", exitCode)
} else {
ctx.Log("message", "successfully initialized extension policy settings")
}
ctx.Log("message", "successfully initialized extension policy settings")
} else if os.IsNotExist(err) {
ctx.Log("message", "extension policy settings file does not exist. No policy applied.", "error", err)
extensionPolicyManagerPtr = nil
Expand Down
49 changes: 49 additions & 0 deletions internal/cmds/cmds_test.go
Original file line number Diff line number Diff line change
Expand Up @@ -1697,6 +1697,55 @@ func Test_enable_e2e_extension_policy_settings_block_statusfail(t *testing.T) {
require.True(t, strings.Contains(report[0].Status.FormattedMessage.Message, "executionState\":\"Failed\",\"executionMessage\":\"Execution failed"), "execution message should indicate failure")
}

// This test verifies that an invalid policy file does not block execution,
// and the extension proceeds with no policy applied.
func Test_enable_e2e_extension_policy_settings_corrupt_policy_continues(t *testing.T) {
// Two primary scenarios for corrupt policy: empty file and invalid JSON.
corruptPolicies := map[string][]byte{
"empty file": {},
"invalid json": []byte("{ this is not valid json"),
}

for name, corruptContent := range corruptPolicies {
t.Run(name, func(t *testing.T) {
ctx := log.NewContext(log.NewNopLogger())
extName, seqNum := "corruptPolicyRun", 0
scriptContent := []byte("#!/bin/bash\necho hello\n")

srv := make_server_with_content(scriptContent)
defer srv.Close()

dataDir, err := os.MkdirTemp("", "policy-corrupt")
require.Nil(t, err)
defer os.RemoveAll(dataDir)

// Create a valid environment first, then overwrite the policy file with corrupt content.
policy := &extensionpolicysettingsrc.RCv2ExtensionPolicySettings{
LimitScripts: "alloweddownloaded",
}
fakeEnv := setupPolicyE2E(t, dataDir, extName, seqNum, srv.URL+"/script.sh", false, "", "", policy)

// Corrupt the policy file so that loading/parsing it fails.
policyFilePath := filepath.Join(fakeEnv.HandlerEnvironment.ConfigFolder, constants.PolicyFileName)
require.Nil(t, os.WriteFile(policyFilePath, corruptContent, 0600), "could not write corrupt policy file")

scriptWasExecuted := false
RunCmd = func(ctx *log.Context, dir, scriptFilePath string, cfg *handlersettings.HandlerSettings, metadata types.RCMetadata) (error, int) {
scriptWasExecuted = true
return nil, 0
}

err = commandProcessor.ProcessHandlerCommandWithDetails(ctx, CmdEnable, fakeEnv, extName, seqNum, constants.DownloadFolder, dataDir)
require.Nil(t, err, "enable command should succeed despite corrupt policy")
require.True(t, scriptWasExecuted, "script should still be executed when policy is corrupt")

report := readStatusReport(t, fakeEnv, extName, seqNum) // verify status report exists and is valid
require.Equal(t, types.StatusSuccess, report[0].Status.Status, "status report should indicate success")
require.True(t, strings.Contains(report[0].Status.FormattedMessage.Message, "executionState\":\"Succeeded\",\"executionMessage\":\"Execution completed"), "execution message should indicate success")
})
}
}

func Test_enable_e2e_extension_policy_settings_block_statussuccess_disableOutputBlobs(t *testing.T) {
ctx := log.NewContext(log.NewNopLogger())
extName, seqNum := "badPolicyRun", 0
Expand Down
Loading