summaryrefslogtreecommitdiff
path: root/src/mongo/s/commands
diff options
context:
space:
mode:
authorShreyas Kalyan <shreyas.kalyan@mongodb.com>2023-04-19 17:51:11 -0400
committerEvergreen Agent <no-reply@evergreen.mongodb.com>2023-04-26 20:09:28 +0000
commit4c41d4f602d973733062f5f9b91eaa7de0d3db61 (patch)
tree1dcb0ff60625322b8d8094ac5a148be698e6bb5f /src/mongo/s/commands
parent61fd19ccf20155424fe944dc68b4f2984f483755 (diff)
downloadmongo-4c41d4f602d973733062f5f9b91eaa7de0d3db61.tar.gz
SERVER-72949 Add PrimaryOnlyService for cleanupStructuredEncryptionData
Diffstat (limited to 'src/mongo/s/commands')
-rw-r--r--src/mongo/s/commands/SConscript1
-rw-r--r--src/mongo/s/commands/cluster_fle2_cleanup_cmd.cpp123
2 files changed, 124 insertions, 0 deletions
diff --git a/src/mongo/s/commands/SConscript b/src/mongo/s/commands/SConscript
index 00c6ec73e35..35d64a7435e 100644
--- a/src/mongo/s/commands/SConscript
+++ b/src/mongo/s/commands/SConscript
@@ -58,6 +58,7 @@ env.Library(
'cluster_filemd5_cmd.cpp',
'cluster_find_and_modify_cmd.cpp',
'cluster_find_cmd_s.cpp',
+ 'cluster_fle2_cleanup_cmd.cpp',
'cluster_fle2_compact_cmd.cpp',
'cluster_fle2_get_count_info_cmd.cpp',
'cluster_fsync_cmd.cpp',
diff --git a/src/mongo/s/commands/cluster_fle2_cleanup_cmd.cpp b/src/mongo/s/commands/cluster_fle2_cleanup_cmd.cpp
new file mode 100644
index 00000000000..ea596a2b398
--- /dev/null
+++ b/src/mongo/s/commands/cluster_fle2_cleanup_cmd.cpp
@@ -0,0 +1,123 @@
+/**
+ * Copyright (C) 2022-present MongoDB, Inc.
+ *
+ * This program is free software: you can redistribute it and/or modify
+ * it under the terms of the Server Side Public License, version 1,
+ * as published by MongoDB, Inc.
+ *
+ * This program is distributed in the hope that it will be useful,
+ * but WITHOUT ANY WARRANTY; without even the implied warranty of
+ * MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
+ * Server Side Public License for more details.
+ *
+ * You should have received a copy of the Server Side Public License
+ * along with this program. If not, see
+ * <http://www.mongodb.com/licensing/server-side-public-license>.
+ *
+ * As a special exception, the copyright holders give permission to link the
+ * code of portions of this program with the OpenSSL library under certain
+ * conditions as described in each individual source file and distribute
+ * linked combinations including the program with the OpenSSL library. You
+ * must comply with the Server Side Public License in all respects for
+ * all of the code used other than as permitted herein. If you modify file(s)
+ * with this exception, you may extend this exception to your version of the
+ * file(s), but you are not obligated to do so. If you do not wish to do so,
+ * delete this exception statement from your version. If you delete this
+ * exception statement from all source files in the program, then also delete
+ * it in the license file.
+ */
+
+#include "mongo/platform/basic.h"
+
+#include "mongo/db/auth/authorization_session.h"
+#include "mongo/db/commands.h"
+#include "mongo/db/commands/fle2_cleanup_gen.h"
+#include "mongo/s/cluster_commands_helpers.h"
+#include "mongo/s/grid.h"
+
+namespace mongo {
+namespace {
+
+class ClusterCleanupStructuredEncryptionDataCmd final
+ : public TypedCommand<ClusterCleanupStructuredEncryptionDataCmd> {
+public:
+ using Request = CleanupStructuredEncryptionData;
+ using Reply = CleanupStructuredEncryptionData::Reply;
+
+ class Invocation final : public InvocationBase {
+ public:
+ using InvocationBase::InvocationBase;
+
+ Reply typedRun(OperationContext* opCtx);
+
+ private:
+ bool supportsWriteConcern() const final {
+ return false;
+ }
+
+ void doCheckAuthorization(OperationContext* opCtx) const final {
+ auto* as = AuthorizationSession::get(opCtx->getClient());
+ uassert(ErrorCodes::Unauthorized,
+ "Not authorized to cleanup structured encryption data",
+ as->isAuthorizedForActionsOnResource(
+ ResourcePattern::forExactNamespace(request().getNamespace()),
+ ActionType::cleanupStructuredEncryptionData));
+ }
+
+ NamespaceString ns() const final {
+ return request().getNamespace();
+ }
+ };
+
+ AllowedOnSecondary secondaryAllowed(ServiceContext*) const final {
+ return BasicCommand::AllowedOnSecondary::kNever;
+ }
+
+ bool adminOnly() const final {
+ return false;
+ }
+
+ std::set<StringData> sensitiveFieldNames() const final {
+ return {CleanupStructuredEncryptionData::kCleanupTokensFieldName};
+ }
+} clusterCleanupStructuredEncryptionDataCmd;
+
+using Cmd = ClusterCleanupStructuredEncryptionDataCmd;
+Cmd::Reply Cmd::Invocation::typedRun(OperationContext* opCtx) {
+ CurOp::get(opCtx)->debug().shouldOmitDiagnosticInformation = true;
+
+ auto nss = request().getNamespace();
+ const auto dbInfo =
+ uassertStatusOK(Grid::get(opCtx)->catalogCache()->getDatabase(opCtx, nss.db()));
+
+ // Rewrite command verb to _shardSvrCleanupStructuredEnccryptionData.
+ auto cmd = request().toBSON({});
+ BSONObjBuilder req;
+ for (const auto& elem : cmd) {
+ if (elem.fieldNameStringData() == Request::kCommandName) {
+ req.appendAs(elem, "_shardsvrCleanupStructuredEncryptionData");
+ } else {
+ req.append(elem);
+ }
+ }
+
+ auto response = uassertStatusOK(
+ executeCommandAgainstDatabasePrimary(
+ opCtx,
+ nss.db(),
+ dbInfo,
+ CommandHelpers::appendMajorityWriteConcern(req.obj(), opCtx->getWriteConcern()),
+ ReadPreferenceSetting(ReadPreference::PrimaryOnly),
+ Shard::RetryPolicy::kIdempotent)
+ .swResponse);
+
+ BSONObjBuilder result;
+ CommandHelpers::filterCommandReplyForPassthrough(response.data, &result);
+
+ auto reply = result.obj();
+ uassertStatusOK(getStatusFromCommandResult(reply));
+ return Reply::parse(IDLParserContext{Request::kCommandName}, reply.removeField("ok"_sd));
+}
+
+} // namespace
+} // namespace mongo