Frun1na opened a new issue, #6116:
URL: https://github.com/apache/rocketmq-dashboard/issues/6116

   ### Before Creating the Bug Report
   
   - [x] I have searched the [open 
issues](https://github.com/apache/rocketmq-dashboard/issues) of this repository 
and believe that this is not a duplicate.
   - [x] This is a defect in RocketMQ Studio, not a usage question and not a 
defect in another Apache RocketMQ repository.
   - [x] I can reproduce this on the current `rocketmq-studio` branch, or I 
have stated the exact version I am running below.
   
   ### Studio Version
   
   branch: `rocketmq-studio`
   git commit id: `5e4c39b0`
   deployed as: reproduced by a unit test against that commit 
(`AclUpdateToolHandlerTest`)
   
   ### Runtime Environment
   
   OS: Ubuntu on WSL2
   MySQL: not applicable — the defect is in the MCP/AI tool's argument 
handling, no database involved
   browser (for UI issues): not applicable
   
   ### Connected RocketMQ Cluster
   
   RocketMQ version: not applicable — reproduced with a mocked `AclService` in 
a unit test
   access mode: not applicable
   deployment: the live case is a Tencent Cloud (TDMQ for RocketMQ) instance, 
whose ACL rules are roles without a numeric database id
   
   ### Describe the Bug
   
   `rmq.acl.update` cannot update any ACL rule of a provider whose rules have 
no numeric id — every Tencent Cloud instance:
   
   - `AclUpdateToolHandler.parseId` 
(`handler/acl/AclUpdateToolHandler.java:69-78`) insists on a number: 
`Long.parseLong(id)`, otherwise `ToolError.ACL_ID_INVALID` ("ACL id must be 
numeric: %s", hint "Use the numeric ACL id returned by rmq.acl.list"). Both 
`preview` (line 55) and `execute` (line 66) go through it.
   - But such a rule has no number to pass: since #4574 (`fix(ai): tolerate a 
null id in ACL and user tool outputs`) `rmq.acl.list`/`rmq.acl.get` publish 
Tencent rules with the `id` omitted, and the only usable identifier is the role 
name in `principal`.
   - The service already accepts that name: `AclService.getRule` resolves a 
Tencent rule by `id.equals(rule.getPrincipal())`, and `AclService.updateRule`'s 
Tencent branch (`TencentAclService.updateRule` → `createRule` → `ModifyRole` by 
principal) never asks for an id at all — so the numeric requirement is the 
handler's own, and it contradicts the layer below it.
   - The sibling tools do not have it: `rmq.acl.get` and `rmq.acl.delete` pass 
the identifier straight to `AclService.getRule` / `AclService.deleteRule`, both 
of which accept the principal, so a Tencent rule can be read and deleted 
through the tools but never updated. #4574's commit message states this gap 
explicitly ("that gap is left for a follow-up").
   
   The result for the caller is a dead end whose hint points at a value that 
does not exist: the model is told to use the numeric id from `rmq.acl.list`, 
and that listing carries none for the very instance it is working on.
   
   ### Steps to Reproduce
   
   ```
   cd server
   mvn -B -ntp test -DforkCount=1 -Dtest=AclUpdateToolHandlerTest
   ```
   
   `applyShouldUpdateARuleAddressedByPrincipalTest` stubs 
`AclService.getRule("GID_role", "cluster-1")`, the way `AclService` resolves a 
Tencent rule, and calls
   `handler.execute(new AclMutationInput("cluster-1", "GID_role", "GID_role", 
"TopicB", …), context("cluster-1"))`.
   `planShouldPreviewARuleAddressedByPrincipalTest` does the same through 
`preview` and
   `applyShouldReportAnUnknownRuleFromTheServiceTest` pins that an unknown 
identifier is reported by the
   service. Before the fix the first two fail with
   
   ```
   org.apache.rocketmq.studio.ops.ai.tool.core.ToolExecutionException: ACL id 
must be numeric: GID_role
        at 
org.apache.rocketmq.studio.ops.ai.tool.handler.acl.AclUpdateToolHandler.parseId(AclUpdateToolHandler.java:76)
   ```
   
   from `execute` and from `preview`, and the third never reaches the service 
at all.
   
   ### What Did You Expect to See?
   
   `rmq.acl.update` should accept the same identifier 
`rmq.acl.get`/`rmq.acl.delete` accept and let
   `AclService` decide whether a numeric id is required, so a rule that is 
addressed by its principal can
   be updated. A rule that cannot be resolved should be reported by the service 
(404 for a missing rule,
   400 for a malformed id).
   
   ### What Did You See Instead?
   
   Both the preview and the apply call fail with `ACL id must be numeric: <role 
name>` before the service
   is consulted, so no ACL rule can be updated on such an instance through the 
tool at all.
   
   ### Additional Context
   
   A fix with regression tests follows in a pull request. It also removes 
`ToolError.ACL_ID_INVALID`,
   which loses its only reference with this change.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to