Azure / Azure/azure-linux-extensions
Deploy LinuxDiagnostics using ARM calculated SAS fails
- 主要语言
- Python
- 星标
- 333
- 派生
- 278
- 平均合并
- 2 天 9 小时
- 30 天内合并 PR
- 4
描述
I am unable to deploy the LinuxDiagnotics extension using ARM templates because the SAS token generated by the `listAccountSas()` function in ARM generates expiry date stamps in a format that MdsTime does not support.
My `/var/log/azure/Microsoft.Azure.Diagnostics.LinuxDiagnostic/3.0.113/extension.log` contains the following (note the factional part of the datestamp):
```
2018/09/25 16:09:14 Parse reported these messages:
2018/09/25 16:09:14 /var/lib/waagent/Microsoft.Azure.Diagnostics.LinuxDiagnostic
-3.0.113/xmlCfg.xml(3) Error: Storage credential validation for table storage fa
iled: MdsTime(): expected: RFC3339 date; Actual: decoded='2020-09-19T03:23:47.00
00000Z', original: '2020-09-19T03%3A23%3A47.0000000Z'
```
The simplified ARM template that generates the token is the following,
```
{
"$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
"contentVersion": "1.0.0.0",
"parameters": {
"requestContent": {
"type": "object",
"defaultValue": {
"signedServices": "b",
"signedResourceType": "c",
"signedPermission": "r",
"signedExpiry": "2020-09-19T03:23:47Z",
"signedResourceTypes": "s"
}
}
},
"outputs": {
"accountSAS": {
"type": "object",
"value": "[listAccountSas(resourceId('Microsoft.Storage/storageAccounts', 'mystorage'), '2018-02-01', parameters('requestContent'))]"
}
}
}
```
MdsTime parses the timestamp on the following line,
[/Diagnostic/mdsd/mdsdutil/MdsTime.cc](https://github.com/Azure/azure-linux-extensions/blob/b72b251930fc0d62a65a01cf45b8ee5f0f1532d2/Diagnostic/mdsd/mdsdutil/MdsTime.cc#L17)
```
strptime(decoded.c_str(), "%Y-%m-%dT%TZ", &tm);
```
Where as I understand `%T` is short for `%H:%M:%S` where `%S` is
> %S The second (0–60; 60 may occur for leap seconds; earlier also 61 was allowed).
Which does not include the fractional part.
What gives? I cannot simply remove the fractional part from the stamp since it's signed by the storage account access key, but I cannot change the date signed by the function either since it is added by `listAccountSas()`.
贡献指南
这个仓库没有索引到贡献指南
调研方向
从 /Diagnostic/mdsd/mdsdutil/MdsTime.cc 中引用的 strptime 调用开始,并将其接受的格式与 extension.log 中显示的分数时间戳进行比较。使用提供的 ARM 模板重现生成的 SAS 值,并检查 LinuxDiagnostic 的解析路径。当 listAccountSas() 生成的签名时间戳能够被接受且不会使 SAS 凭据失效时,即表示完成。
由索引模型根据 Issue 内容生成。
评估
- 技术栈
- azure, cpp
- 领域
- backend, cloud
- Issue 类型
- 缺陷
- 难度
- 3/5
- 预计耗时
- 1-2 天
- 活跃度
- 停滞
- 描述清晰度
- 基本清楚
- 新手友好度
- 25/100