Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 3 additions & 3 deletions Private/Assert-PfbAdminNameNotCoerced.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -33,9 +33,9 @@ function Assert-PfbAdminNameNotCoerced {
the silent-misbinding class this guard exists to remove. The imperative throw
terminates the pipeline, which is the required behaviour.

Unlike Assert-PfbRemoteNameNotCoerced this returns NOTHING on success. That helper
ends with `return $true` and its callers invoke it bare, so it leaks a stray True
into each cmdlet's success stream. Do not reintroduce that here.
This imperative assertion helper returns NOTHING on success and reports failure
only through a terminating throw. Callers invoke it bare, so any success-stream
value it returned would leak into the cmdlet's own output.
#>
param([Parameter(Mandatory)] [object]$Value)

Expand Down
1 change: 0 additions & 1 deletion Private/Assert-PfbRemoteNameNotCoerced.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -46,5 +46,4 @@ function Assert-PfbRemoteNameNotCoerced {
'Select-Object -ExpandProperty name | Get-PfbArrayConnectionPath, or pass -RemoteName explicitly.'
}
}
return $true
}
2 changes: 1 addition & 1 deletion Public/Network/Invoke-PfbNetworkPing.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -40,7 +40,7 @@ function Invoke-PfbNetworkPing {
begin { Assert-PfbConnection -Array ([ref]$Array) }
process {
$queryParams = @{ 'destination' = $Destination }
if ($SourceName) { $queryParams['source.name'] = $SourceName }
if ($SourceName) { $queryParams['source'] = $SourceName }
if ($Count -gt 0) { $queryParams['count'] = $Count }
if ($PacketSize -gt 0) { $queryParams['packet_size'] = $PacketSize }
Invoke-PfbApiRequest -Array $Array -Method GET -Endpoint 'network-interfaces/ping' -QueryParams $queryParams
Expand Down
2 changes: 1 addition & 1 deletion Public/Network/Invoke-PfbNetworkTrace.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -39,7 +39,7 @@ function Invoke-PfbNetworkTrace {
begin { Assert-PfbConnection -Array ([ref]$Array) }
process {
$queryParams = @{ 'destination' = $Destination }
if ($SourceName) { $queryParams['source.name'] = $SourceName }
if ($SourceName) { $queryParams['source'] = $SourceName }
if ($Method) { $queryParams['method'] = $Method }
Invoke-PfbApiRequest -Array $Array -Method GET -Endpoint 'network-interfaces/trace' -QueryParams $queryParams
}
Expand Down
19 changes: 14 additions & 5 deletions Public/ObjectStore/New-PfbObjectStoreAccessPolicyRule.ps1
Original file line number Diff line number Diff line change
Expand Up @@ -8,26 +8,29 @@ function New-PfbObjectStoreAccessPolicyRule {
constraints.
.PARAMETER PolicyName
The name of the access policy to which the rule will be added.
.PARAMETER Name
The name of the rule to create. The REST endpoint requires a rule name,
so this parameter is mandatory.
.PARAMETER Attributes
A hashtable of rule properties including effect, actions, resources,
and conditions.
.PARAMETER Array
The FlashBlade connection object.
.EXAMPLE
New-PfbObjectStoreAccessPolicyRule -PolicyName "full-access-policy" -Attributes @{
New-PfbObjectStoreAccessPolicyRule -PolicyName "full-access-policy" -Name "get-put-all" -Attributes @{
effect = "allow"
actions = @("s3:GetObject", "s3:PutObject")
resources = @("*")
}
Creates a rule allowing get and put operations on all resources.
.EXAMPLE
New-PfbObjectStoreAccessPolicyRule -PolicyName "readonly-policy" -Attributes @{
New-PfbObjectStoreAccessPolicyRule -PolicyName "readonly-policy" -Name "read-only" -Attributes @{
effect = "allow"
actions = @("s3:GetObject", "s3:ListBucket")
}
Creates a read-only rule in the specified policy.
.EXAMPLE
New-PfbObjectStoreAccessPolicyRule -PolicyName "deny-delete-policy" -Attributes @{
New-PfbObjectStoreAccessPolicyRule -PolicyName "deny-delete-policy" -Name "no-deletes" -Attributes @{
effect = "deny"
actions = @("s3:DeleteObject")
resources = @("*")
Expand All @@ -39,6 +42,9 @@ function New-PfbObjectStoreAccessPolicyRule {
[Parameter(Mandatory, Position = 0)]
[string]$PolicyName,

[Parameter(Mandatory, Position = 1)]
[string]$Name,

[Parameter()]
[hashtable]$Attributes,

Expand All @@ -48,9 +54,12 @@ function New-PfbObjectStoreAccessPolicyRule {
Assert-PfbConnection -Array ([ref]$Array)

$body = if ($Attributes) { $Attributes } else { @{} }
$queryParams = @{ 'policy_names' = $PolicyName }
$queryParams = @{
'names' = $Name
'policy_names' = $PolicyName
}

if ($PSCmdlet.ShouldProcess($PolicyName, 'Create access policy rule')) {
if ($PSCmdlet.ShouldProcess($Name, 'Create access policy rule')) {
Invoke-PfbApiRequest -Array $Array -Method POST -Endpoint 'object-store-access-policies/rules' -Body $body -QueryParams $queryParams
}
}
61 changes: 29 additions & 32 deletions Reports/PfbApiDriftReport.json
Original file line number Diff line number Diff line change
Expand Up @@ -4058,8 +4058,7 @@
"missingQueryParameters": [
"component_name",
"print_latency",
"resolve_hostname",
"source"
"resolve_hostname"
],
"missingBodyProperties": [],
"readOnlyFields": [],
Expand All @@ -4081,8 +4080,7 @@
"discover_mtu",
"fragment_packet",
"port",
"resolve_hostname",
"source"
"resolve_hostname"
],
"missingBodyProperties": [],
"readOnlyFields": [],
Expand Down Expand Up @@ -11825,7 +11823,6 @@
"missingQueryParameters": [
"context_names",
"enforce_action_restrictions",
"names",
"policy_ids"
],
"missingBodyProperties": [
Expand All @@ -11840,7 +11837,7 @@
"enumStatus": "not-found-in-resource",
"target": {
"file": "Public/ObjectStore/New-PfbObjectStoreAccessPolicyRule.ps1",
"paramBlockLine": 45,
"paramBlockLine": 51,
"payloadVariable": "body",
"assignmentStyle": "unknown",
"hasAttributes": true
Expand All @@ -11857,7 +11854,7 @@
"enumStatus": "no-spec-enum-found",
"target": {
"file": "Public/ObjectStore/New-PfbObjectStoreAccessPolicyRule.ps1",
"paramBlockLine": 45,
"paramBlockLine": 51,
"payloadVariable": "body",
"assignmentStyle": "unknown",
"hasAttributes": true
Expand All @@ -11877,7 +11874,7 @@
"enumStatus": "matched",
"target": {
"file": "Public/ObjectStore/New-PfbObjectStoreAccessPolicyRule.ps1",
"paramBlockLine": 45,
"paramBlockLine": 51,
"payloadVariable": "body",
"assignmentStyle": "unknown",
"hasAttributes": true
Expand All @@ -11894,7 +11891,7 @@
"enumStatus": "no-spec-enum-found",
"target": {
"file": "Public/ObjectStore/New-PfbObjectStoreAccessPolicyRule.ps1",
"paramBlockLine": 45,
"paramBlockLine": 51,
"payloadVariable": "body",
"assignmentStyle": "unknown",
"hasAttributes": true
Expand Down Expand Up @@ -14620,8 +14617,8 @@
},
{
"name": "names",
"endpointCount": 24,
"queryEndpointCount": 24,
"endpointCount": 23,
"queryEndpointCount": 23,
"bodyEndpointCount": 0,
"endpoints": [
"GET /arrays/clients/performance",
Expand All @@ -14646,7 +14643,6 @@
"PATCH /syslog-servers/settings",
"POST /maintenance-windows",
"POST /object-store-access-keys",
"POST /object-store-access-policies/rules",
"POST /object-store-roles/object-store-trust-policies/rules"
],
"annotations": []
Expand Down Expand Up @@ -15369,18 +15365,6 @@
],
"annotations": []
},
{
"name": "source",
"endpointCount": 3,
"queryEndpointCount": 2,
"bodyEndpointCount": 1,
"endpoints": [
"GET /network-interfaces/ping",
"GET /network-interfaces/trace",
"POST /keytabs"
],
"annotations": []
},
{
"name": "storage_class_names",
"endpointCount": 3,
Expand Down Expand Up @@ -17165,6 +17149,16 @@
],
"annotations": []
},
{
"name": "source",
"endpointCount": 1,
"queryEndpointCount": 0,
"bodyEndpointCount": 1,
"endpoints": [
"POST /keytabs"
],
"annotations": []
},
{
"name": "sp",
"endpointCount": 1,
Expand Down Expand Up @@ -17279,7 +17273,7 @@
"conventionStrength": [
{
"name": "names",
"cmdletCount": 300,
"cmdletCount": 301,
"cmdlets": [
"Get-PfbActiveDirectory",
"Get-PfbAdmin",
Expand Down Expand Up @@ -17418,6 +17412,7 @@
"New-PfbNfsExportPolicy",
"New-PfbNlmReclamation",
"New-PfbObjectStoreAccessPolicy",
"New-PfbObjectStoreAccessPolicyRule",
"New-PfbObjectStoreAccount",
"New-PfbObjectStoreRemoteCredential",
"New-PfbObjectStoreRole",
Expand Down Expand Up @@ -19146,6 +19141,15 @@
"Remove-PfbFileSystemReplicaLink"
]
},
{
"name": "source",
"cmdletCount": 3,
"cmdlets": [
"Invoke-PfbNetworkPing",
"Invoke-PfbNetworkTrace",
"New-PfbFileSystem"
]
},
{
"name": "actions",
"cmdletCount": 2,
Expand Down Expand Up @@ -19729,13 +19733,6 @@
"New-PfbNfsExportRule"
]
},
{
"name": "source",
"cmdletCount": 1,
"cmdlets": [
"New-PfbFileSystem"
]
},
{
"name": "sp",
"cmdletCount": 1,
Expand Down
10 changes: 5 additions & 5 deletions Reports/PfbApiDriftReport.md
Original file line number Diff line number Diff line change
Expand Up @@ -23,7 +23,7 @@ This report accepts **false positives in order to eliminate false negatives**. A
- Uncovered endpoints: 95
- Endpoints with parameter gaps: 439
- Missing body properties (addable): 426
- Missing query parameters (addable): 883
- Missing query parameters (addable): 880
- Read-only body fields (not addable -- see the Read-only fields section below): 384
- Phantom fields silently excluded (accumulated in the capability map, absent from the newest analysed spec): 40
- Partial-confidence endpoints (see `How to read this report` above, and each row's marker in the Parameter gaps table): 61
Expand All @@ -47,7 +47,7 @@ Showing the top 25 of 241 findings by endpoint count -- the full list is in the
| `allow_errors` | 118 | 118 | 0 | 0 | not yet implemented; deferred to Phase 2 |
| `ids` | 38 | 38 | 0 | 220 | |
| `sort` | 28 | 28 | 0 | 179 | |
| `names` | 24 | 24 | 0 | 300 | |
| `names` | 23 | 23 | 0 | 301 | |
| `total_only` | 17 | 17 | 0 | 12 | |
| `policy_ids` | 16 | 16 | 0 | 97 | |
| `member_ids` | 14 | 14 | 0 | 81 | |
Expand Down Expand Up @@ -254,8 +254,8 @@ Endpoints an existing cmdlet already calls, where the capability map knows of a
| `GET /network-interfaces/connectors/settings` | Get-PfbNetworkInterfaceConnectorSettings | ids | | `high` | |
| `GET /network-interfaces/neighbors` | Get-PfbNetworkInterfaceNeighbor | total_item_count | | `high` | |
| `GET /network-interfaces/network-connection-statistics` | Get-PfbNetworkConnectionStatistics | current_state, local_host, local_port, remote_host, remote_port | | `high` | |
| `GET /network-interfaces/ping` | Invoke-PfbNetworkPing | component_name, print_latency, resolve_hostname, source | | `high` | |
| `GET /network-interfaces/trace` | Invoke-PfbNetworkTrace | component_name, discover_mtu, fragment_packet, port, resolve_hostname, source | | `high` | |
| `GET /network-interfaces/ping` | Invoke-PfbNetworkPing | component_name, print_latency, resolve_hostname | | `high` | |
| `GET /network-interfaces/trace` | Invoke-PfbNetworkTrace | component_name, discover_mtu, fragment_packet, port, resolve_hostname | | `high` | |
| `GET /nfs-export-policies` | Get-PfbNfsExportPolicy | allow_errors, context_names, workload_ids, workload_names | | `high` | |
| `GET /nfs-export-policies/rules` | Get-PfbNfsExportRule | allow_errors, context_names, ids | | `high` | |
| `GET /node-groups/nodes` | Get-PfbNodeGroupNode | node_group_ids, node_group_names, node_ids, node_names | | `high` | |
Expand Down Expand Up @@ -466,7 +466,7 @@ Endpoints an existing cmdlet already calls, where the capability map knows of a
| `POST /object-store-access-policies` | New-PfbObjectStoreAccessPolicy | context_names, enforce_action_restrictions | description, rules | `high` | |
| `POST /object-store-access-policies/object-store-roles` | New-PfbObjectStoreAccessPolicyRole | context_names, member_ids, policy_ids | | `high` | |
| `POST /object-store-access-policies/object-store-users` | New-PfbObjectStoreAccessPolicyUser | context_names, member_ids, policy_ids | | `high` | |
| `POST /object-store-access-policies/rules` | New-PfbObjectStoreAccessPolicyRule | context_names, enforce_action_restrictions, names, policy_ids | actions, conditions, effect, resources | `high` | |
| `POST /object-store-access-policies/rules` | New-PfbObjectStoreAccessPolicyRule | context_names, enforce_action_restrictions, policy_ids | actions, conditions, effect, resources | `high` | |
| `POST /object-store-account-exports` | New-PfbObjectStoreAccountExport | context_names | | `high` | |
| `POST /object-store-accounts` | New-PfbObjectStoreAccount | context_names | account_exports, bucket_defaults, hard_limit_enabled, quota_limit | `high` | |
| `POST /object-store-remote-credentials` | New-PfbObjectStoreRemoteCredential | context_names | access_key_id, secret_access_key | `high` | |
Expand Down
43 changes: 4 additions & 39 deletions Reports/PfbDeadKeyReport.json
Original file line number Diff line number Diff line change
@@ -1,10 +1,10 @@
{
"specVersion": "2.28",
"counts": {
"parametersInventoried": 2164,
"keysEvaluated": 1746,
"ok": 1661,
"deadKey": 85,
"parametersInventoried": 2165,
"keysEvaluated": 1747,
"ok": 1664,
"deadKey": 83,
"skipReasons": {
"wire name unresolved": 126,
"body property": 278,
Expand Down Expand Up @@ -1102,41 +1102,6 @@
"names"
]
},
{
"severity": "WRONG-RESULTS",
"cmdlet": "Invoke-PfbNetworkPing",
"parameter": "SourceName",
"wireKey": "source.name",
"method": "GET",
"endpoint": "network-interfaces/ping",
"declared": [
"component_name",
"count",
"destination",
"packet_size",
"print_latency",
"resolve_hostname",
"source"
]
},
{
"severity": "WRONG-RESULTS",
"cmdlet": "Invoke-PfbNetworkTrace",
"parameter": "SourceName",
"wireKey": "source.name",
"method": "GET",
"endpoint": "network-interfaces/trace",
"declared": [
"component_name",
"destination",
"discover_mtu",
"fragment_packet",
"method",
"port",
"resolve_hostname",
"source"
]
},
{
"severity": "CREATE",
"cmdlet": "New-PfbNlmReclamation",
Expand Down
14 changes: 12 additions & 2 deletions Reports/PfbFieldCmdletMap.json
Original file line number Diff line number Diff line change
Expand Up @@ -11130,7 +11130,7 @@
{
"cmdlet": "Invoke-PfbNetworkPing",
"parameter": "SourceName",
"wireName": "source.name",
"wireName": "source",
"status": "no-spec-enum-found",
"matchedKey": null,
"specValues": null,
Expand All @@ -11150,7 +11150,7 @@
{
"cmdlet": "Invoke-PfbNetworkTrace",
"parameter": "SourceName",
"wireName": "source.name",
"wireName": "source",
"status": "no-spec-enum-found",
"matchedKey": null,
"specValues": null,
Expand Down Expand Up @@ -12827,6 +12827,16 @@
"stableSinceOldestVersion": null,
"recommendation": null
},
{
"cmdlet": "New-PfbObjectStoreAccessPolicyRule",
"parameter": "Name",
"wireName": "names",
"status": "no-spec-enum-found",
"matchedKey": null,
"specValues": null,
"stableSinceOldestVersion": null,
"recommendation": null
},
{
"cmdlet": "New-PfbObjectStoreAccessPolicyRule",
"parameter": "PolicyName",
Expand Down
2 changes: 1 addition & 1 deletion Reports/PfbFieldCmdletMapping.md
Original file line number Diff line number Diff line change
Expand Up @@ -9,7 +9,7 @@ Reporting only -- no `Public/` cmdlet is edited by this script. Every `matched`
- matched: 2
- collision: 1
- not-found-in-resource: 29
- no-spec-enum-found: 1971
- no-spec-enum-found: 1972

| Cmdlet | Parameter | Wire name | Status | Spec values | Recommendation |
|---|---|---|---|---|---|
Expand Down
Loading
Loading