Extends the agent, ingest, storage, api, and web with Windows Event Log/ETW sourcing and Tantivy-backed free-text search, per the approved Phase 1 plan. - CLAUDE.md: materialized on disk (never existed as a file before) with a new Phase 1 "done looks like" section. - agent: Windows Event Log (EvtSubscribe) and ETW sources, Windows service wrapper (install/uninstall/run-service), both feature- and target_os-gated so Linux builds/tests/clippy stay unaffected. Also fixed two pre-existing Phase 0 clippy gaps (dead-code on default-features-only builds, a type-inference edge case) found while testing every feature combination properly for the first time. UNVERIFIED on real Windows -- no Windows toolchain existed anywhere in the build environment; flagged prominently in three places. - proto/ingest: new record_id field, assigned once server-side in ingest's gRPC front end so ClickHouse and Tantivy agree on the same ID for the same record. - storage: record_id column + bloom filter index, verified against a live ClickHouse. - search: new service, Tantivy index, rskafka consumer as an independent second consumer group on the same Redpanda topic ingest already reads. - api/web: new /search endpoint and page, sharing the query page's result-table shape and component. - hack/windows-fixture: sends realistic Windows-shaped data straight to ingest, so the pipeline's handling of it is verifiable without a Windows host. Verified end-to-end on the live docker-compose stack: the same record_id comes back from both /query and /search for the same log line, including for windows-fixture's synthetic Windows Event Log data. Real bugs found and fixed along the way: api/Dockerfile missing proto/ in its build context, search's logs being completely silent (RUST_LOG gap), and search/target/ missing from .gitignore/.dockerignore.
151 lines
3.7 KiB
Go
151 lines
3.7 KiB
Go
package queryapi
|
|
|
|
import (
|
|
"context"
|
|
"encoding/json"
|
|
"errors"
|
|
"io"
|
|
"log/slog"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
"time"
|
|
)
|
|
|
|
type fakeExecutor struct {
|
|
result *QueryResult
|
|
err error
|
|
gotSQL string
|
|
}
|
|
|
|
func (f *fakeExecutor) Execute(_ context.Context, sql string) (*QueryResult, error) {
|
|
f.gotSQL = sql
|
|
if f.err != nil {
|
|
return nil, f.err
|
|
}
|
|
return f.result, nil
|
|
}
|
|
|
|
type fakeSearchClient struct {
|
|
recordIDs []string
|
|
err error
|
|
}
|
|
|
|
func (f *fakeSearchClient) Search(_ context.Context, _ string, _ uint32) ([]string, error) {
|
|
if f.err != nil {
|
|
return nil, f.err
|
|
}
|
|
return f.recordIDs, nil
|
|
}
|
|
|
|
func newTestHandler(exec queryExecutor) *Handler {
|
|
return newTestHandlerWithSearch(exec, &fakeSearchClient{})
|
|
}
|
|
|
|
func newTestHandlerWithSearch(exec queryExecutor, search searchClient) *Handler {
|
|
return NewHandler(slog.New(slog.NewTextHandler(io.Discard, nil)), exec, search, time.Second, "*")
|
|
}
|
|
|
|
func TestHandleQuerySuccess(t *testing.T) {
|
|
fe := &fakeExecutor{result: &QueryResult{
|
|
Columns: []string{"host", "count"},
|
|
Rows: [][]any{{"h1", 3}},
|
|
}}
|
|
h := newTestHandler(fe)
|
|
|
|
body := strings.NewReader(`{"sql": "SELECT host, count(*) FROM logs GROUP BY host"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/query", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
|
|
}
|
|
var got QueryResult
|
|
if err := json.Unmarshal(rec.Body.Bytes(), &got); err != nil {
|
|
t.Fatalf("decoding response: %v", err)
|
|
}
|
|
if len(got.Columns) != 2 || len(got.Rows) != 1 {
|
|
t.Fatalf("unexpected result: %+v", got)
|
|
}
|
|
if fe.gotSQL != "SELECT host, count(*) FROM logs GROUP BY host" {
|
|
t.Fatalf("executor received unexpected SQL: %q", fe.gotSQL)
|
|
}
|
|
}
|
|
|
|
func TestHandleQueryRejectsNonSelect(t *testing.T) {
|
|
fe := &fakeExecutor{}
|
|
h := newTestHandler(fe)
|
|
|
|
body := strings.NewReader(`{"sql": "DELETE FROM logs"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/query", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("status = %d, want 400", rec.Code)
|
|
}
|
|
if fe.gotSQL != "" {
|
|
t.Fatal("executor should not have been called for a rejected query")
|
|
}
|
|
}
|
|
|
|
func TestHandleQueryRejectsInvalidJSON(t *testing.T) {
|
|
h := newTestHandler(&fakeExecutor{})
|
|
|
|
body := strings.NewReader(`not json`)
|
|
req := httptest.NewRequest(http.MethodPost, "/query", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("status = %d, want 400", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestHandleQueryExecutorErrorReturnsBadGateway(t *testing.T) {
|
|
fe := &fakeExecutor{err: errors.New("boom")}
|
|
h := newTestHandler(fe)
|
|
|
|
body := strings.NewReader(`{"sql": "SELECT 1"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/query", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusBadGateway {
|
|
t.Fatalf("status = %d, want 502", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestHandleHealthz(t *testing.T) {
|
|
h := newTestHandler(&fakeExecutor{})
|
|
req := httptest.NewRequest(http.MethodGet, "/healthz", nil)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestCORSPreflight(t *testing.T) {
|
|
h := newTestHandler(&fakeExecutor{})
|
|
req := httptest.NewRequest(http.MethodOptions, "/query", nil)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusNoContent {
|
|
t.Fatalf("status = %d, want 204", rec.Code)
|
|
}
|
|
if got := rec.Header().Get("Access-Control-Allow-Origin"); got != "*" {
|
|
t.Fatalf("Access-Control-Allow-Origin = %q, want *", got)
|
|
}
|
|
}
|