Skip to content

Commit b9e48b6

Browse files
committed
Made evaluation_order in body common control configurable via Augments
This exposes evaluation_order in body common control of the main policy (promises.cf) via default:def.control_common_evaluation_order, which sets the default promise evaluation order for all components (cf-agent, cf-serverd, cf-execd, cf-monitord). body agent control now only sets evaluation_order for cf-agent when it is explicitly configured via augments, so cf-agent inherits the evaluation order from body common control unless overridden. This keeps the existing default:def.control_agent_evaluation_order override working while letting body common control act as the base default. Acceptance tests exercise both the common control default (inherited by cf-agent) and the cf-agent specific override against the built promises.cf. Ticket: ENT-13495 Changelog: Title
1 parent 97a950f commit b9e48b6

8 files changed

Lines changed: 237 additions & 18 deletions

File tree

‎MPF.md‎

Lines changed: 27 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -708,16 +708,39 @@ To override the default for **cf-agent** configure `default:update_def.control_a
708708
The following settings are defined in `controls/def.cf` can be set from an
709709
[augments file][Augments].
710710

711+
### Configure the default promise evaluation order for all components
712+
713+
By default CFEngine processes promises in "Normal Order". Configure `default:def.control_common_evaluation_order` to control the default promise evaluation order for all components (`cf-agent`, `cf-serverd`, `cf-execd` and `cf-monitord`). This variable is used to set `evaluation_order` in `body common control` in `promises.cf`. Override it for a specific component (for example `cf-agent`, see below) or for a specific file (with `evaluation_order` in `body file control`).
714+
715+
Example Augments:
716+
717+
```json
718+
{
719+
"variables": {
720+
"default:def.control_common_evaluation_order": {
721+
"value": "top_down",
722+
"comment": "Our policy writers find it easier to understand policy that is evaluated in the order it is written."
723+
}
724+
}
725+
}
726+
```
727+
728+
**History:**
729+
730+
- Introduced in 3.28.0.
731+
732+
**See also:** [Policy evaluation ordering](reference/language-concepts/policy-evaluation/), [Configure the evaluation order of cf-agent for main policy](#Configure the evaluation order of cf-agent for main policy), [`evaluation_order` in `body common control`][cf-agent#evaluation_order], [Policy style guide on promise ordering][Policy style guide#Promise ordering]
733+
711734
### Configure the evaluation order of cf-agent for main policy
712735

713-
By default CFEngine processes promises in "Normal Order". Configure `default:def.control_agent_evaluation_order` to control the default promise evaluation order for `cf-agent`. This variable is used to set `evaluation_order` in `body agent control` in `promises.cf`
736+
By default `cf-agent` inherits the promise evaluation order from `body common control` (see [Configure the default promise evaluation order for all components](#Configure the default promise evaluation order for all components)). Configure `default:def.control_agent_evaluation_order` to control the promise evaluation order for `cf-agent` specifically, overriding `body common control`. This variable is used to set `evaluation_order` in `body agent control` in `promises.cf` and is only applied when set to a valid value (`classic` or `top_down`) via augments.
714737

715738
Example Augments:
716739

717740
```json
718741
{
719742
"variables": {
720-
"default:def.control_agent_evalution_order": {
743+
"default:def.control_agent_evaluation_order": {
721744
"value": "top_down",
722745
"comment": "Our policy writers find it easier to understand policy that is evaluated in the order it is written."
723746
}
@@ -728,8 +751,9 @@ Example Augments:
728751
**History:**
729752

730753
- Introduced in 3.27.0.
754+
- Since 3.28.0, `cf-agent` inherits the evaluation order from `body common control` when `default:def.control_agent_evaluation_order` is not set.
731755

732-
**See also:** [Policy evaluation ordering](reference/language-concepts/policy-evaluation/), [Configure cf-agent promise evaluation order for update policy](#Configure the evaluation order for cf-agent evaluated promises for update policy), [Policy style guide on promise ordering][Policy style guide#Promise ordering]
756+
**See also:** [Policy evaluation ordering](reference/language-concepts/policy-evaluation/), [Configure the default promise evaluation order for all components](#Configure the default promise evaluation order for all components), [Configure cf-agent promise evaluation order for update policy](#Configure the evaluation order for cf-agent evaluated promises for update policy), [Policy style guide on promise ordering][Policy style guide#Promise ordering]
733757

734758
### Automatically migrate ignore_interfaces.rx to workdir
735759

‎controls/cf_agent.cf‎

Lines changed: 8 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -11,10 +11,6 @@ body agent control
1111
# Global default for time that must elapse before promise will be rechecked.
1212
# Don't keep any promises.
1313
any::
14-
@if minimum_version(3.27.0)
15-
# The order in which promises are evaluated (top_down|classic)
16-
evaluation_order => "$(default:def.control_agent_evaluation_order)";
17-
@endif
1814
# Minimum time (in minutes) which should have passed since the last time
1915
# the promise was verified before it is checked again.
2016
ifelapsed => "1";
@@ -58,4 +54,12 @@ body agent control
5854
# Environment variables based on Distro
5955
control_agent_agentfacility_configured::
6056
agentfacility => "$(default:def.control_agent_agentfacility)";
57+
@if minimum_version(3.27.0)
58+
# Only override cf-agent's promise evaluation order when explicitly
59+
# configured via augments; otherwise cf-agent inherits the order set in
60+
# body common control. See ENT-13495.
61+
control_agent_evaluation_order_configured::
62+
# The order in which promises are evaluated (top_down|classic)
63+
evaluation_order => "$(default:def.control_agent_evaluation_order)";
64+
@endif
6165
}

‎controls/def.cf‎

Lines changed: 9 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -275,17 +275,6 @@ bundle common def
275275
if => and("enterprise_edition", "am_policy_hub");
276276

277277
# Agent Controls
278-
"control_agent_evaluation_order" -> { "ENT-13495" }
279-
string => ifelse(
280-
isvariable($(this.promiser)),
281-
"$(default:def.control_agent_evaluation_order)",
282-
"classic"
283-
),
284-
comment => concat(
285-
'We default to the classic "Normal Order"',
286-
' for cf-agent if not otherwise specified'
287-
);
288-
289278
"control_agent_update_evaluation_order" -> { "ENT-13495" }
290279
string => ifelse(
291280
isvariable($(this.promiser)),
@@ -451,6 +440,15 @@ bundle common def
451440
" control for setting agentfacility"
452441
);
453442

443+
"control_agent_evaluation_order_configured" -> { "ENT-13495" }
444+
expression => isvariable("default:def.control_agent_evaluation_order"),
445+
comment => concat(
446+
"cf-agent overrides body common control's promise evaluation order",
447+
" only when default:def.control_agent_evaluation_order is set via",
448+
" augments. Otherwise cf-agent inherits the evaluation order from body",
449+
" common control"
450+
);
451+
454452
"_control_agent_environment_vars_validated" -> { "CFE-3927" }
455453
and => {
456454
# The variable must be defined

‎promises.cf.in‎

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -133,6 +133,15 @@ body common control
133133
# The number of minutes after which last-seen entries are purged from cf_lastseen.lmdb
134134
lastseenexpireafter => "$(def.control_common_lastseenexpireafter)";
135135

136+
@if minimum_version(3.27.0)
137+
# The order in which promises are evaluated (top_down|classic). Sets the
138+
# default evaluation order for all components. Override it for a specific
139+
# component (e.g. cf-agent in body agent control) or file (body file
140+
# control). Defaults to the classic "Normal Order" unless
141+
# default:def.control_common_evaluation_order is set via augments.
142+
evaluation_order => "$(default:def.control_common_evaluation_order)";
143+
@endif
144+
136145
control_common_tls_min_version_defined::
137146
tls_min_version => "$(default:def.control_common_tls_min_version)"; # See also: allowtlsversion in body server control
138147

Lines changed: 85 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,85 @@
1+
# Tests that default:def.control_agent_evaluation_order set via augments
2+
# changes cf-agent's promise evaluation order via body agent control
3+
# (ENT-13495).
4+
#
5+
# Only the agent control augment is set. The eo_discriminator bundle (appended
6+
# to the bundlesequence via control_common_bundlesequence_end) prints EARLY
7+
# before LATE in classic (Normal) order, and LATE before EARLY in top_down
8+
# order, so the order of the reports reveals the evaluation order in effect.
9+
body common control
10+
{
11+
inputs => { "../../default.sub.cf" };
12+
bundlesequence => { default("$(this.promise_filename)") };
13+
version => "1.0";
14+
}
15+
16+
#######################################################
17+
bundle agent test
18+
{
19+
vars:
20+
"files_to_copy"
21+
slist => {
22+
"cfe_internal",
23+
"controls",
24+
"inventory",
25+
"lib",
26+
"promises.cf",
27+
"services",
28+
};
29+
30+
files:
31+
"$(sys.inputdir)/." create => "true";
32+
33+
"$(sys.inputdir)/$(files_to_copy)"
34+
copy_from => dcs_sync(
35+
"$(this.promise_dirname)/../../../../$(files_to_copy)"
36+
),
37+
perms => m(600),
38+
depth_search => recurse("inf");
39+
40+
methods:
41+
""
42+
usebundle => file_make(
43+
"$(sys.inputdir)/secondary.cf",
44+
'
45+
bundle agent eo_discriminator
46+
{
47+
reports:
48+
eo_marker::
49+
"ENT13495_EO_EARLY";
50+
51+
classes:
52+
"eo_marker" expression => "any";
53+
54+
reports:
55+
any::
56+
"ENT13495_EO_LATE";
57+
}
58+
'
59+
);
60+
61+
""
62+
usebundle => file_copy(
63+
"$(this.promise_filename).json", "$(sys.inputdir)/def.json"
64+
);
65+
}
66+
67+
#######################################################
68+
bundle agent check
69+
{
70+
vars:
71+
# Only keep the discriminator's reports so the order check is not defeated
72+
# by the (large) rest of the policy output.
73+
"command"
74+
string => "$(sys.cf_agent) -Kf $(sys.inputdir)/promises.cf 2>/dev/null | grep ENT13495_EO";
75+
76+
methods:
77+
# In top_down order LATE is reported before EARLY.
78+
""
79+
usebundle => dcs_passif_output(
80+
"(?s).*ENT13495_EO_LATE.*ENT13495_EO_EARLY.*",
81+
"",
82+
$(command),
83+
$(this.promise_filename)
84+
);
85+
}
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
{
2+
"inputs": ["$(sys.inputdir)/secondary.cf"],
3+
"vars": { "control_common_bundlesequence_end": ["eo_discriminator"] },
4+
"variables": {
5+
"default:def.control_agent_evaluation_order": { "value": "top_down" }
6+
}
7+
}
Lines changed: 85 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,85 @@
1+
# Tests that default:def.control_common_evaluation_order set via augments
2+
# changes the promise evaluation order for all components (ENT-13495).
3+
#
4+
# Here only the common control augment is set (not the agent one), so cf-agent
5+
# must inherit "top_down" from body common control. The eo_discriminator bundle
6+
# (appended to the bundlesequence via control_common_bundlesequence_end) prints
7+
# EARLY before LATE in classic (Normal) order, and LATE before EARLY in top_down
8+
# order, so the order of the reports reveals the evaluation order in effect.
9+
body common control
10+
{
11+
inputs => { "../../default.sub.cf" };
12+
bundlesequence => { default("$(this.promise_filename)") };
13+
version => "1.0";
14+
}
15+
16+
#######################################################
17+
bundle agent test
18+
{
19+
vars:
20+
"files_to_copy"
21+
slist => {
22+
"cfe_internal",
23+
"controls",
24+
"inventory",
25+
"lib",
26+
"promises.cf",
27+
"services",
28+
};
29+
30+
files:
31+
"$(sys.inputdir)/." create => "true";
32+
33+
"$(sys.inputdir)/$(files_to_copy)"
34+
copy_from => dcs_sync(
35+
"$(this.promise_dirname)/../../../../$(files_to_copy)"
36+
),
37+
perms => m(600),
38+
depth_search => recurse("inf");
39+
40+
methods:
41+
""
42+
usebundle => file_make(
43+
"$(sys.inputdir)/secondary.cf",
44+
'
45+
bundle agent eo_discriminator
46+
{
47+
reports:
48+
eo_marker::
49+
"ENT13495_EO_EARLY";
50+
51+
classes:
52+
"eo_marker" expression => "any";
53+
54+
reports:
55+
any::
56+
"ENT13495_EO_LATE";
57+
}
58+
'
59+
);
60+
61+
""
62+
usebundle => file_copy(
63+
"$(this.promise_filename).json", "$(sys.inputdir)/def.json"
64+
);
65+
}
66+
67+
#######################################################
68+
bundle agent check
69+
{
70+
vars:
71+
# Only keep the discriminator's reports so the order check is not defeated
72+
# by the (large) rest of the policy output.
73+
"command"
74+
string => "$(sys.cf_agent) -Kf $(sys.inputdir)/promises.cf 2>/dev/null | grep ENT13495_EO";
75+
76+
methods:
77+
# In top_down order LATE is reported before EARLY.
78+
""
79+
usebundle => dcs_passif_output(
80+
"(?s).*ENT13495_EO_LATE.*ENT13495_EO_EARLY.*",
81+
"",
82+
$(command),
83+
$(this.promise_filename)
84+
);
85+
}
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
{
2+
"inputs": ["$(sys.inputdir)/secondary.cf"],
3+
"vars": { "control_common_bundlesequence_end": ["eo_discriminator"] },
4+
"variables": {
5+
"default:def.control_common_evaluation_order": { "value": "top_down" }
6+
}
7+
}

0 commit comments

Comments
 (0)