Extends the agent, ingest, storage, api, and web with Windows Event Log/ETW sourcing and Tantivy-backed free-text search, per the approved Phase 1 plan. - CLAUDE.md: materialized on disk (never existed as a file before) with a new Phase 1 "done looks like" section. - agent: Windows Event Log (EvtSubscribe) and ETW sources, Windows service wrapper (install/uninstall/run-service), both feature- and target_os-gated so Linux builds/tests/clippy stay unaffected. Also fixed two pre-existing Phase 0 clippy gaps (dead-code on default-features-only builds, a type-inference edge case) found while testing every feature combination properly for the first time. UNVERIFIED on real Windows -- no Windows toolchain existed anywhere in the build environment; flagged prominently in three places. - proto/ingest: new record_id field, assigned once server-side in ingest's gRPC front end so ClickHouse and Tantivy agree on the same ID for the same record. - storage: record_id column + bloom filter index, verified against a live ClickHouse. - search: new service, Tantivy index, rskafka consumer as an independent second consumer group on the same Redpanda topic ingest already reads. - api/web: new /search endpoint and page, sharing the query page's result-table shape and component. - hack/windows-fixture: sends realistic Windows-shaped data straight to ingest, so the pipeline's handling of it is verifiable without a Windows host. Verified end-to-end on the live docker-compose stack: the same record_id comes back from both /query and /search for the same log line, including for windows-fixture's synthetic Windows Event Log data. Real bugs found and fixed along the way: api/Dockerfile missing proto/ in its build context, search's logs being completely silent (RUST_LOG gap), and search/target/ missing from .gitignore/.dockerignore.
126 lines
3.5 KiB
Go
126 lines
3.5 KiB
Go
package queryapi
|
|
|
|
import (
|
|
"encoding/json"
|
|
"errors"
|
|
"net/http"
|
|
"net/http/httptest"
|
|
"strings"
|
|
"testing"
|
|
)
|
|
|
|
func TestHandleSearchSuccess(t *testing.T) {
|
|
id := "5754b062-ec8b-45b1-b1b8-a50f263adcd3"
|
|
fe := &fakeExecutor{result: &QueryResult{
|
|
Columns: []string{"message"},
|
|
Rows: [][]any{{"hello world"}},
|
|
}}
|
|
fs := &fakeSearchClient{recordIDs: []string{id}}
|
|
h := newTestHandlerWithSearch(fe, fs)
|
|
|
|
body := strings.NewReader(`{"query": "hello"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/search", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
|
|
}
|
|
if !strings.Contains(fe.gotSQL, id) {
|
|
t.Fatalf("expected the record_id in the generated SQL, got %q", fe.gotSQL)
|
|
}
|
|
if !strings.Contains(fe.gotSQL, "WHERE record_id IN") {
|
|
t.Fatalf("expected an IN clause, got %q", fe.gotSQL)
|
|
}
|
|
|
|
var got QueryResult
|
|
if err := json.Unmarshal(rec.Body.Bytes(), &got); err != nil {
|
|
t.Fatalf("decoding response: %v", err)
|
|
}
|
|
if len(got.Rows) != 1 {
|
|
t.Fatalf("unexpected result: %+v", got)
|
|
}
|
|
}
|
|
|
|
func TestHandleSearchRejectsEmptyQuery(t *testing.T) {
|
|
fe := &fakeExecutor{}
|
|
fs := &fakeSearchClient{}
|
|
h := newTestHandlerWithSearch(fe, fs)
|
|
|
|
body := strings.NewReader(`{"query": " "}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/search", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusBadRequest {
|
|
t.Fatalf("status = %d, want 400", rec.Code)
|
|
}
|
|
if fe.gotSQL != "" {
|
|
t.Fatal("executor should not have been called for an empty query")
|
|
}
|
|
}
|
|
|
|
func TestHandleSearchNoResultsReturnsEmptyNotError(t *testing.T) {
|
|
fe := &fakeExecutor{}
|
|
fs := &fakeSearchClient{recordIDs: nil}
|
|
h := newTestHandlerWithSearch(fe, fs)
|
|
|
|
body := strings.NewReader(`{"query": "nothing matches this"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/search", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusOK {
|
|
t.Fatalf("status = %d, want 200; body=%s", rec.Code, rec.Body.String())
|
|
}
|
|
if fe.gotSQL != "" {
|
|
t.Fatal("executor should not have been called when search returns no IDs")
|
|
}
|
|
|
|
var got QueryResult
|
|
if err := json.Unmarshal(rec.Body.Bytes(), &got); err != nil {
|
|
t.Fatalf("decoding response: %v", err)
|
|
}
|
|
if len(got.Rows) != 0 {
|
|
t.Fatalf("expected empty rows, got %+v", got.Rows)
|
|
}
|
|
}
|
|
|
|
func TestHandleSearchServiceErrorReturnsBadGateway(t *testing.T) {
|
|
fe := &fakeExecutor{}
|
|
fs := &fakeSearchClient{err: errors.New("search service unreachable")}
|
|
h := newTestHandlerWithSearch(fe, fs)
|
|
|
|
body := strings.NewReader(`{"query": "hello"}`)
|
|
req := httptest.NewRequest(http.MethodPost, "/search", body)
|
|
rec := httptest.NewRecorder()
|
|
|
|
h.Routes().ServeHTTP(rec, req)
|
|
|
|
if rec.Code != http.StatusBadGateway {
|
|
t.Fatalf("status = %d, want 502", rec.Code)
|
|
}
|
|
}
|
|
|
|
func TestRecordIDsQuerySkipsInvalidUUIDs(t *testing.T) {
|
|
sql, err := recordIDsQuery([]string{"not-a-uuid", "5754b062-ec8b-45b1-b1b8-a50f263adcd3"})
|
|
if err != nil {
|
|
t.Fatalf("recordIDsQuery() error = %v", err)
|
|
}
|
|
if strings.Contains(sql, "not-a-uuid") {
|
|
t.Fatalf("expected the invalid UUID to be skipped, got %q", sql)
|
|
}
|
|
if !strings.Contains(sql, "5754b062-ec8b-45b1-b1b8-a50f263adcd3") {
|
|
t.Fatalf("expected the valid UUID to be included, got %q", sql)
|
|
}
|
|
}
|
|
|
|
func TestRecordIDsQueryAllInvalidReturnsError(t *testing.T) {
|
|
if _, err := recordIDsQuery([]string{"not-a-uuid", "also-not-one"}); err == nil {
|
|
t.Fatal("expected an error when no IDs are valid UUIDs")
|
|
}
|
|
}
|