Azure / Azure/azure-linux-extensions

Deploy LinuxDiagnostics using ARM calculated SAS fails

オープン
#653 コメント 3 件 リアクション 1 件 担当者 0 名 GitHub で見る
主要言語
Python
スター
333
フォーク
278
平均マージ
2日 9時間
マージ済み PR(30日)
4

説明

I am unable to deploy the LinuxDiagnotics extension using ARM templates because the SAS token generated by the `listAccountSas()` function in ARM generates expiry date stamps in a format that MdsTime does not support.

My `/var/log/azure/Microsoft.Azure.Diagnostics.LinuxDiagnostic/3.0.113/extension.log` contains the following (note the factional part of the datestamp):

```
2018/09/25 16:09:14 Parse reported these messages:
2018/09/25 16:09:14 /var/lib/waagent/Microsoft.Azure.Diagnostics.LinuxDiagnostic
-3.0.113/xmlCfg.xml(3) Error: Storage credential validation for table storage fa
iled: MdsTime(): expected: RFC3339 date; Actual: decoded='2020-09-19T03:23:47.00
00000Z', original: '2020-09-19T03%3A23%3A47.0000000Z'
```

The simplified ARM template that generates the token is the following,

```
{
"$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"requestContent": {
"type": "object",
"defaultValue": {
"signedServices": "b",
"signedResourceType": "c",
"signedPermission": "r",
"signedExpiry": "2020-09-19T03:23:47Z",
"signedResourceTypes": "s"
}
}
},
"outputs": {
"accountSAS": {
"type": "object",
"value": "[listAccountSas(resourceId('Microsoft.Storage/storageAccounts', 'mystorage'), '2018-02-01', parameters('requestContent'))]"
}
}
}
```

MdsTime parses the timestamp on the following line,

[/Diagnostic/mdsd/mdsdutil/MdsTime.cc](https://github.com/Azure/azure-linux-extensions/blob/b72b251930fc0d62a65a01cf45b8ee5f0f1532d2/Diagnostic/mdsd/mdsdutil/MdsTime.cc#L17)
```
strptime(decoded.c_str(), "%Y-%m-%dT%TZ", &tm);
```

Where as I understand `%T` is short for `%H:%M:%S` where `%S` is

> %S The second (0–60; 60 may occur for leap seconds; earlier also 61 was allowed).

Which does not include the fractional part.

What gives? I cannot simply remove the fractional part from the stamp since it's signed by the storage account access key, but I cannot change the date signed by the function either since it is added by `listAccountSas()`.

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

調査の方向性

Start with /Diagnostic/mdsd/mdsdutil/MdsTime.cc at the referenced strptime call and compare its accepted format with the fractional timestamp shown in extension.log. Reproduce the generated SAS value using the supplied ARM template and inspect the LinuxDiagnostic parsing path. Done means the signed timestamp produced by listAccountSas() is accepted without invalidating the SAS credential.

索引モデルが issue の本文から書いたものです。

評価

技術スタック
azure, cpp
領域
backend, cloud
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
おおむね明確
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。