Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
18 changes: 12 additions & 6 deletions includes/database.php
Original file line number Diff line number Diff line change
Expand Up @@ -299,6 +299,15 @@ function plugin_evidence_upgrade_database() {
$current = $info['version'];
$oldv = db_fetch_cell('SELECT version FROM plugin_config WHERE directory = "evidence"');

// The plugin's library directory moved from include/ to includes/. Repoint
// any plugin_hooks row still bound to the old path on every check - not only
// during a version-change upgrade - because an install whose version was
// already bumped without its hooks being repointed would otherwise keep
// loading the stale include/<file> path (or, once include/ is deleted, fail
// Cacti's plugin file-inclusion security check for it) on every page. The
// LIKE filter makes this a no-op on healthy installs.
db_execute("UPDATE plugin_hooks SET file = REPLACE(file, 'include/', 'includes/') WHERE name = 'evidence' AND file LIKE 'include/%'");
Comment thread
TheWitness marked this conversation as resolved.

if (!cacti_version_compare($oldv, $current, '=')) {
if (cacti_version_compare($oldv, '0.3', '<')) {
$data = [];
Expand All @@ -313,12 +322,9 @@ function plugin_evidence_upgrade_database() {
api_plugin_db_table_create('evidence', 'plugin_evidence_snmp_info', $data);
}

// The plugin's library directory moved from include/ to includes/; repoint
// any hook still registered against the old path so existing installs load
// them from the new location after upgrade.
db_execute("UPDATE plugin_hooks SET file = REPLACE(file, 'include/', 'includes/') WHERE name = 'evidence' AND file LIKE 'include/%'");
// Remove files tombstoned in manifest.json (the old include/ tree).
evidence_prune_files();
// Remove files tombstoned in manifest.json (the old include/ tree).
evidence_prune_files();

// Set the new version
db_execute_prepared("UPDATE plugin_config
SET version = ?, author = ?, webpage = ?
Expand Down
14 changes: 12 additions & 2 deletions tests/Unit/EvidenceLifecycleTest.php
Original file line number Diff line number Diff line change
Expand Up @@ -41,13 +41,23 @@
expect($drops)->toHaveCount(7);
});

it('does nothing when the stored version already matches the plugin version', function () {
it('repoints stale include/ hooks even when the stored version already matches', function () {
$info = plugin_evidence_version();

evidence_test_mock_db('db_fetch_cell', 'plugin_config', $info['version']);

expect(plugin_evidence_check_config())->toBeTrue();
expect($GLOBALS['__test_db_calls'])->toBeEmpty();

// On an up-to-date install the only work is the idempotent include/ ->
// includes/ plugin_hooks repoint; no schema migration or version write runs.
expect($GLOBALS['__test_db_calls'])->toHaveCount(1);

$call = $GLOBALS['__test_db_calls'][0];

expect($call['fn'])->toBe('db_execute')
->and($call['sql'])->toContain('UPDATE plugin_hooks')
->and($call['sql'])->toContain("REPLACE(file, 'include/', 'includes/')")
->and($call['sql'])->toContain("file LIKE 'include/%'");
});

it('updates the stored plugin_config version when it drifts', function () {
Expand Down
Loading