Skip to content

[Test] OpenProxy 권한 조회의 복제 지연 재현 - #363

Merged
Gimini-3 merged 3 commits into
developfrom
test/opensql-permission-replica-lag
Sep 30, 2026
Merged

Gimini-3 merged 3 commits into
developfrom
test/opensql-permission-replica-lag

Conversation

@Gimini-3

@Gimini-3 Gimini-3 commented Sep 29, 2026 •

Copy link
Copy Markdown
Contributor

Closes #362

결과

  • 실제 DocGrid HTTP 인가 경로에서 권한 회수 후 OpenProxy 조회가 두 번 모두 200을 반환했습니다. 같은 시점 primary 직결 대조군과 복제 정상화 후 대조군은 403이었습니다.
  • 역할 SQL은 지연된 standby에 도착했고, Redis에는 옛 ADMIN이 다시 캐시됐습니다. 두 standby의 WAL receive/replay LSN 차이와 정상 원복을 기록했습니다.
  • Patroni가 SQL replay pause와 ALTER SYSTEM 설정을 자동으로 되돌리는 실패 사례도 보존했습니다.

변경

  • Patroni 로컬 recovery_conf를 사용하는 root 전용 임시 지연·자동 원복 가드
  • 일회용 계정, 노드별 SQL 통계·LSN, 두 JVM/Redis HTTP 대조군 실행 스크립트
  • 비식별 설계·사전 시험·두 번의 유효 실행 결과 문서

검증

  • GCP 기존 3노드에서 유효한 HTTP 시험 2회: STALE_ADMIN_ALLOWED 재현
  • 종료 후 양 standby 지연 0, streaming, WAL backlog 0, 시험 계정 0
  • Python unittest 17개, Python AST·Bash 문법, git diff --check 통과

이번 PR은 취약점 재현과 원복 증거만 포함합니다. 권한 조회 primary 고정, Redis 경쟁 수정, WebSocket·HA 장애 전환은 별도 작업입니다. 프로젝트 ID·내부 IP·계정·비밀번호·토큰·원본 앱 로그는 포함하지 않았습니다.

후속 안전장치·재검증

  • 독립 systemd 타이머로 시험 ADMIN 계정을 정리하고, 지연된 두 standby에는 임시 nofailover를 적용합니다. 원본 Patroni 설정은 root 전용 영속 백업으로 보관합니다.
  • cleanup 실패는 관측값과 별도로 전체 실행을 INVALID로 판정합니다. 단순 403은 안전성 증거가 아니므로 실제 standby SQL 도착과 두 대조군을 요구합니다.
  • 새 실행 53688fbe7475는 동일 run ID·코드 커밋·JAR/설치 helper/live preflight 해시로 원장을 연결합니다. OpenProxy 경유 M=200 및 stale ADMIN 재캐시, primary 직결·복제 복구 대조군=403이 재현됐습니다.
  • 종료 후 두 standby 모두 지연 0·nofailover 해제·streaming·backlog 0, 시험 계정 0을 재확인했습니다. 원장 16건: 14건 2xx, 예상된 403 2건, 결과 불명 0건. 관련 단위 테스트 14개·OpenSQL 스크립트 전체 25개 통과.
  • 두 standby를 승격 후보에서 제외한 구간에는 primary 상실 시 자동 failover가 불가능할 수 있습니다. 이번에는 primary 장애를 주입하지 않았습니다. transient timer의 실제 만료와 VM 재부팅·node1 상실도 미검증이며, 인가 결함은 아직 수정하지 않았습니다.
  • 비식별 실행 결과: docs/test-results/opensql-permission-replica-lag-safety-20261001.md

Add guarded Patroni-managed standby delay, HTTP permission controls, and redacted two-run evidence. Relates to #362.
@coderabbitai

coderabbitai Bot commented Sep 29, 2026 •

Copy link
Copy Markdown

Important

  • 🔍 Trigger review

This repository does not receive automatic reviews because it has fewer than 10 stars.

⚙️ Run configuration

Configuration used: Repository: DocGrid/docgrid/.coderabbit.yaml

Review profile: CHILL

Plan: Advanced

Run ID: c3468a94-6734-46ed-bc35-109fbd751a41

  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Gimini-3
Gimini-3 merged commit 8c3c1a4 into develop Sep 30, 2026
1 check passed
@Gimini-3 Gimini-3 self-assigned this Oct 1, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[Test] OpenProxy 권한 조회의 복제 지연 재현

1 participant