Add trace logs

This commit is contained in:
binwiederhier
2026-06-01 20:30:05 -04:00
parent e18329a17e
commit ae27172f8d
4 changed files with 34 additions and 13 deletions
+23 -1
View File
@@ -53,18 +53,40 @@ func newAccessCache() *accessCache {
func (c *accessCache) Lookup(usernameOrEveryone, topic string) (read, write, found bool) {
escapedTopic := escapeUnderscore(topic)
c.mu.RLock()
defer c.mu.RUnlock()
if usernameOrEveryone != Everyone {
if entry, ok := c.pickBestNoLock(usernameOrEveryone, topic, escapedTopic); ok {
c.mu.RUnlock()
traceACLDecision(usernameOrEveryone, usernameOrEveryone, topic, entry.read, entry.write)
return entry.read, entry.write, true
}
}
if entry, ok := c.pickBestNoLock(Everyone, topic, escapedTopic); ok {
c.mu.RUnlock()
traceACLDecision(usernameOrEveryone, Everyone, topic, entry.read, entry.write)
return entry.read, entry.write, true
}
c.mu.RUnlock()
traceACLDecision(usernameOrEveryone, "", topic, false, false)
return false, false, false
}
// traceACLDecision logs an ACL lookup result
func traceACLDecision(requestUser, matchedUser, topic string, read, write bool) {
ev := log.Tag(tag).
Field("user_name", requestUser).
Field("topic", topic).
Field("read", read).
Field("write", write)
if !ev.IsTrace() {
return
}
if matchedUser == "" {
ev.Trace("ACL no match")
return
}
ev.Field("matched_user", matchedUser).Trace("ACL match")
}
// Reload scans (user_name, topic, read, write) rows and merges them into the
// cache. With no usernames the cache is replaced wholesale; otherwise the
// query is invoked with those usernames as positional args and only the
+4 -5
View File
@@ -748,10 +748,10 @@ func (a *Manager) AllowReservation(username string, topic string) error {
// The found return value indicates whether an ACL entry was found at all.
//
// Priority:
// - specific user beats Everyone
// - longer pattern beats shorter (a more specific rule beats a more general one,
// - Specific user beats Everyone
// - Longer pattern beats shorter (a more specific rule beats a more general one,
// e.g. "test*" > "*")
// - write beats read at equal length
// - Write beats read at equal length
//
// When AccessCacheEnabled is true (config), the lookup is served entirely from
// the in-memory snapshot maintained by accessCache. Otherwise the original SQL
@@ -1634,11 +1634,10 @@ func (a *Manager) maybeProvisionTokens(tx *sql.Tx, provisionUsernames []string,
}
// Close stops background goroutines and closes the underlying database.
// Safe to call multiple times.
func (a *Manager) Close() error {
select {
case <-a.quit:
// already closed
// Already closed
default:
close(a.quit)
}