From 616032bced172331dfd36768f31b3da091299d43 Mon Sep 17 00:00:00 2001 From: Zac Bergquist Date: Tue, 12 Sep 2023 10:18:23 -0600 Subject: [PATCH] Fix some lint warnings (#31740) Including redundant types in composite literals and duplicate imports in the same file. --- api/types/plugin_test.go | 2 +- integration/integration_test.go | 22 ++++++++--------- lib/auth/auth_with_roles_test.go | 33 +++++++++++++------------- lib/auth/register.go | 13 +++++----- lib/services/label_expressions_test.go | 12 +++++----- 5 files changed, 40 insertions(+), 42 deletions(-) diff --git a/api/types/plugin_test.go b/api/types/plugin_test.go index 8003cfc2a14..755f508d89e 100644 --- a/api/types/plugin_test.go +++ b/api/types/plugin_test.go @@ -688,7 +688,7 @@ func TestPluginDiscordValidation(t *testing.T) { return &PluginSpecV1_Discord{ &PluginDiscordSettings{ RoleToRecipients: map[string]*DiscordChannels{ - "*": &DiscordChannels{ChannelIds: []string{"1234567890"}}, + "*": {ChannelIds: []string{"1234567890"}}, }, }, } diff --git a/integration/integration_test.go b/integration/integration_test.go index 8f3c89846be..942ab6b310d 100644 --- a/integration/integration_test.go +++ b/integration/integration_test.go @@ -64,7 +64,6 @@ import ( "github.com/gravitational/teleport/api/client/proto" "github.com/gravitational/teleport/api/constants" "github.com/gravitational/teleport/api/defaults" - apidefaults "github.com/gravitational/teleport/api/defaults" "github.com/gravitational/teleport/api/metadata" tracessh "github.com/gravitational/teleport/api/observability/tracing/ssh" "github.com/gravitational/teleport/api/profile" @@ -94,7 +93,6 @@ import ( "github.com/gravitational/teleport/lib/service/servicecfg" "github.com/gravitational/teleport/lib/services" "github.com/gravitational/teleport/lib/session" - rsession "github.com/gravitational/teleport/lib/session" "github.com/gravitational/teleport/lib/srv/alpnproxy/common" "github.com/gravitational/teleport/lib/sshutils" "github.com/gravitational/teleport/lib/tlsca" @@ -4055,7 +4053,7 @@ func testDiscovery(t *testing.T, suite *integrationTestSuite) { } // we need to wait until we know about the node because direct dial to // unregistered servers is no longer supported - _, err := site.GetNode(ctx, apidefaults.Namespace, main.Config.HostUUID) + _, err := site.GetNode(ctx, defaults.Namespace, main.Config.HostUUID) assert.NoError(t, err) }, time.Minute, 250*time.Millisecond) @@ -7669,8 +7667,8 @@ func testJoinOverReverseTunnelOnly(t *testing.T, suite *integrationTestSuite) { t.Cleanup(cancel) dialer := apiclient.NewDialer( ctx, - apidefaults.DefaultIdleTimeout, - apidefaults.DefaultIOTimeout, + defaults.DefaultIdleTimeout, + defaults.DefaultIOTimeout, ) tlsConfig := utils.TLSConfig(nil) tlsConfig.InsecureSkipVerify = true @@ -8099,12 +8097,12 @@ func testAgentlessConn(t *testing.T, tc, joinTC *client.TeleportClient, node *ty // forward SSH agent sshClient := nodeClient.Client.Client - session, err := sshClient.NewSession() + s, err := sshClient.NewSession() require.NoError(t, err) t.Cleanup(func() { // the SSH server will close the session to avoid a deadlock, // so closing it here will result in io.EOF if the test passes - _ = session.Close() + _ = s.Close() }) // this is essentially what agent.ForwardToAgent does, but we're @@ -8126,12 +8124,12 @@ func testAgentlessConn(t *testing.T, tc, joinTC *client.TeleportClient, node *ty } }() - require.NoError(t, agent.RequestAgentForwarding(session)) + require.NoError(t, agent.RequestAgentForwarding(s)) // request a shell so Teleport starts tracking this session - session.Stderr = io.Discard - session.Stdout = io.Discard - require.NoError(t, session.Shell()) + s.Stderr = io.Discard + s.Stdout = io.Discard + require.NoError(t, s.Shell()) var sessTracker types.SessionTracker require.Eventually(t, func() bool { @@ -8145,7 +8143,7 @@ func testAgentlessConn(t *testing.T, tc, joinTC *client.TeleportClient, node *ty }, 3*time.Second, 100*time.Millisecond) // test that attempting to join the session returns an error - err = joinTC.Join(ctx, types.SessionPeerMode, tc.Namespace, rsession.ID(sessTracker.GetSessionID()), nil) + err = joinTC.Join(ctx, types.SessionPeerMode, tc.Namespace, session.ID(sessTracker.GetSessionID()), nil) require.True(t, trace.IsBadParameter(err)) require.ErrorContains(t, err, "session joining is only supported for Teleport nodes, not OpenSSH nodes") diff --git a/lib/auth/auth_with_roles_test.go b/lib/auth/auth_with_roles_test.go index 7ec0b58ce06..a3de2eda0c9 100644 --- a/lib/auth/auth_with_roles_test.go +++ b/lib/auth/auth_with_roles_test.go @@ -54,7 +54,6 @@ import ( "github.com/gravitational/teleport/lib/auth/testauthority" "github.com/gravitational/teleport/lib/authz" "github.com/gravitational/teleport/lib/defaults" - libdefaults "github.com/gravitational/teleport/lib/defaults" "github.com/gravitational/teleport/lib/events" "github.com/gravitational/teleport/lib/events/eventstest" "github.com/gravitational/teleport/lib/modules" @@ -197,15 +196,15 @@ func TestLocalUserCanReissueCerts(t *testing.T) { renewable: true, // expiration is allowed to be pushed out into the future, // but no more than the maximum renewable cert TTL - reqTTL: 2 * libdefaults.MaxRenewableCertTTL, - expiresIn: libdefaults.MaxRenewableCertTTL, + reqTTL: 2 * defaults.MaxRenewableCertTTL, + expiresIn: defaults.MaxRenewableCertTTL, }, { desc: "not-renewable-role-requests-max-renew", renewable: false, roleRequests: true, - reqTTL: 2 * libdefaults.MaxRenewableCertTTL, - expiresIn: libdefaults.MaxRenewableCertTTL, + reqTTL: 2 * defaults.MaxRenewableCertTTL, + expiresIn: defaults.MaxRenewableCertTTL, }, } { t.Run(test.desc, func(t *testing.T) { @@ -1736,7 +1735,7 @@ func TestDatabasesCRUDRBAC(t *testing.T) { Name: "dev", Labels: map[string]string{"env": "dev", types.OriginLabel: types.OriginDynamic}, }, types.DatabaseSpecV3{ - Protocol: libdefaults.ProtocolPostgres, + Protocol: defaults.ProtocolPostgres, URI: "localhost:5432", }) require.NoError(t, err) @@ -1744,7 +1743,7 @@ func TestDatabasesCRUDRBAC(t *testing.T) { Name: "admin", Labels: map[string]string{"env": "prod", types.OriginLabel: types.OriginDynamic}, }, types.DatabaseSpecV3{ - Protocol: libdefaults.ProtocolMySQL, + Protocol: defaults.ProtocolMySQL, URI: "localhost:3306", }) require.NoError(t, err) @@ -1851,7 +1850,7 @@ func TestDatabasesCRUDRBAC(t *testing.T) { Name: "cloud1", Labels: map[string]string{"env": "prod", types.OriginLabel: types.OriginCloud}, }, types.DatabaseSpecV3{ - Protocol: libdefaults.ProtocolMySQL, + Protocol: defaults.ProtocolMySQL, URI: "localhost:3306", }) require.NoError(t, err) @@ -1869,7 +1868,7 @@ func TestDatabasesCRUDRBAC(t *testing.T) { Name: "cloud2", Labels: map[string]string{"env": "prod", types.OriginLabel: types.OriginCloud}, }, types.DatabaseSpecV3{ - Protocol: libdefaults.ProtocolMySQL, + Protocol: defaults.ProtocolMySQL, URI: "localhost:3306", DynamicLabels: map[string]types.CommandLabelV2{ "hostname": { @@ -2620,12 +2619,12 @@ func TestIsMFARequiredMFADB(t *testing.T) { }{ { name: "RequireSessionMFA on MySQL protocol doesn't match database name", - dbProtocol: libdefaults.ProtocolMySQL, + dbProtocol: defaults.ProtocolMySQL, req: &proto.IsMFARequiredRequest{ Target: &proto.IsMFARequiredRequest_Database{ Database: &proto.RouteToDatabase{ ServiceName: databaseName, - Protocol: libdefaults.ProtocolMySQL, + Protocol: defaults.ProtocolMySQL, Username: userName, Database: "example", }, @@ -2644,12 +2643,12 @@ func TestIsMFARequiredMFADB(t *testing.T) { }, { name: "RequireSessionMFA off", - dbProtocol: libdefaults.ProtocolMySQL, + dbProtocol: defaults.ProtocolMySQL, req: &proto.IsMFARequiredRequest{ Target: &proto.IsMFARequiredRequest_Database{ Database: &proto.RouteToDatabase{ ServiceName: databaseName, - Protocol: libdefaults.ProtocolMySQL, + Protocol: defaults.ProtocolMySQL, Username: userName, Database: "example", }, @@ -2668,12 +2667,12 @@ func TestIsMFARequiredMFADB(t *testing.T) { }, { name: "RequireSessionMFA on Postgres protocol database name doesn't match", - dbProtocol: libdefaults.ProtocolPostgres, + dbProtocol: defaults.ProtocolPostgres, req: &proto.IsMFARequiredRequest{ Target: &proto.IsMFARequiredRequest_Database{ Database: &proto.RouteToDatabase{ ServiceName: databaseName, - Protocol: libdefaults.ProtocolPostgres, + Protocol: defaults.ProtocolPostgres, Username: userName, Database: "example", }, @@ -2692,12 +2691,12 @@ func TestIsMFARequiredMFADB(t *testing.T) { }, { name: "RequireSessionMFA on Postgres protocol database name matches", - dbProtocol: libdefaults.ProtocolPostgres, + dbProtocol: defaults.ProtocolPostgres, req: &proto.IsMFARequiredRequest{ Target: &proto.IsMFARequiredRequest_Database{ Database: &proto.RouteToDatabase{ ServiceName: databaseName, - Protocol: libdefaults.ProtocolPostgres, + Protocol: defaults.ProtocolPostgres, Username: userName, Database: "example", }, diff --git a/lib/auth/register.go b/lib/auth/register.go index d73691d05de..8b3208e6c30 100644 --- a/lib/auth/register.go +++ b/lib/auth/register.go @@ -205,7 +205,8 @@ func Register(params RegisterParams) (*proto.Certs, error) { } // add EC2 Identity Document to params if required for given join method - if params.JoinMethod == types.JoinMethodEC2 { + switch params.JoinMethod { + case types.JoinMethodEC2: if !aws.IsEC2NodeID(params.ID.HostUUID) { return nil, trace.BadParameter( `Host ID %q is not valid when using the EC2 join method, `+ @@ -217,27 +218,27 @@ func Register(params RegisterParams) (*proto.Certs, error) { if err != nil { return nil, trace.Wrap(err) } - } else if params.JoinMethod == types.JoinMethodGitHub { + case types.JoinMethodGitHub: params.IDToken, err = githubactions.NewIDTokenSource().GetIDToken(ctx) if err != nil { return nil, trace.Wrap(err) } - } else if params.JoinMethod == types.JoinMethodGitLab { + case types.JoinMethodGitLab: params.IDToken, err = gitlab.NewIDTokenSource(os.Getenv).GetIDToken() if err != nil { return nil, trace.Wrap(err) } - } else if params.JoinMethod == types.JoinMethodCircleCI { + case types.JoinMethodCircleCI: params.IDToken, err = circleci.GetIDToken(os.Getenv) if err != nil { return nil, trace.Wrap(err) } - } else if params.JoinMethod == types.JoinMethodKubernetes { + case types.JoinMethodKubernetes: params.IDToken, err = kubernetestoken.GetIDToken(os.Getenv, os.ReadFile) if err != nil { return nil, trace.Wrap(err) } - } else if params.JoinMethod == types.JoinMethodGCP { + case types.JoinMethodGCP: params.IDToken, err = gcp.GetIDToken(ctx) if err != nil { return nil, trace.Wrap(err) diff --git a/lib/services/label_expressions_test.go b/lib/services/label_expressions_test.go index cc79933efc6..f9ae16de0e9 100644 --- a/lib/services/label_expressions_test.go +++ b/lib/services/label_expressions_test.go @@ -212,7 +212,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_any match", expr: `contains_any(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "skunkworks", "algorithms"}, + "projects": {"parser", "skunkworks", "algorithms"}, }, resourceLabels: map[string]string{ "project-name": "skunkworks", @@ -224,7 +224,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_any no match", expr: `contains_any(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "algorithms"}, + "projects": {"parser", "algorithms"}, }, resourceLabels: map[string]string{ "project-name": "skunkworks", @@ -246,7 +246,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_any empty second arg", expr: `contains_any(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "algorithms"}, + "projects": {"parser", "algorithms"}, }, resourceLabels: map[string]string{ "team": "security", @@ -257,7 +257,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_all match", expr: `contains_all(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "skunkworks", "algorithms"}, + "projects": {"parser", "skunkworks", "algorithms"}, }, resourceLabels: map[string]string{ "project-primary": "parser", @@ -269,7 +269,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_all no match", expr: `contains_all(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "skunkworks", "algorithms"}, + "projects": {"parser", "skunkworks", "algorithms"}, }, resourceLabels: map[string]string{ "project-primary": "parser", @@ -293,7 +293,7 @@ func TestLabelExpressions(t *testing.T) { desc: "contains_all empty second arg", expr: `contains_all(user.spec.traits["projects"], labels_matching("project-*"))`, userTraits: map[string][]string{ - "projects": []string{"parser", "skunkworks", "algorithms"}, + "projects": {"parser", "skunkworks", "algorithms"}, }, // This resource seems unrelated to the contains_all expression. To // avoid footguns, contains_all intentionally returns false when the