From c60f802580c30ec0fa2f0466ae6b376260964f11 Mon Sep 17 00:00:00 2001 From: George K Date: Fri, 30 Jan 2026 11:21:27 -0800 Subject: [PATCH] fix(coderd/rbac): make workspace ACL disabled flag atomic (#21799) The flag is a package-global that was only meant to be set once on startup. This was a bad assumption since the lack of sync caused test flakes. Related to: https://github.com/coder/internal/issues/1317 https://github.com/coder/internal/issues/1318 --- coderd/rbac/object.go | 7 ++++--- 1 file changed, 4 insertions(+), 3 deletions(-) diff --git a/coderd/rbac/object.go b/coderd/rbac/object.go index 476673a980..a3f4b5d740 100644 --- a/coderd/rbac/object.go +++ b/coderd/rbac/object.go @@ -3,6 +3,7 @@ package rbac import ( "fmt" "strings" + "sync/atomic" "github.com/google/uuid" "golang.org/x/xerrors" @@ -239,16 +240,16 @@ func (z Object) WithGroupACL(groups map[string][]policy.Action) Object { // TODO(geokat): similar to builtInRoles, this should ideally be // scoped to a coderd rather than a global. -var workspaceACLDisabled bool +var workspaceACLDisabled atomic.Bool // SetWorkspaceACLDisabled disables/enables workspace sharing for the // deployment. func SetWorkspaceACLDisabled(v bool) { - workspaceACLDisabled = v + workspaceACLDisabled.Store(v) } // WorkspaceACLDisabled returns true if workspace sharing is disabled // for the deployment. func WorkspaceACLDisabled() bool { - return workspaceACLDisabled + return workspaceACLDisabled.Load() }