[ 
https://issues.apache.org/jira/browse/NIFI-16399?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=18121364#comment-18121364
 ] 

Mike Thomsen commented on NIFI-16399:
-------------------------------------

[~exceptionfactory] Thanks, and agreed that the goal is worth doing right. I 
think the temp file-based solution is still the right way to go through with 
this for ExecuteStreamCommand because I think it's the only way to balance all 
of the relevant factors for this particular processor.

The first serious drawback I see with having a stdout protocol is we cannot 
rely on the assumption that people who want to shell out via 
ExecuteStreamCommand have control over the tools they're using to a point where 
they can update them. Having any sort of protocol could be highly problematic 
for them, which is why I proposed this as an optional feature with a simple 
JSON contract that aligns with how NiFi internally treats attributes.

In my opinion, the protocol also has a problem of committing people to write 
scripts, CLI tools, etc. that they want to use in their flows in a very 
NiFi-centric way. It's much less friendly to someone who wants to put a quick 
if statement in their script/tool that checks for an env variable, does the 
attribute drop and moves on, because it binds them to a protocol with NiFi.

I also ran across this, where GitHub did something similar when they discovered 
that their stdout protocol had problems with content injection: 
https://github.blog/changelog/2022-10-11-github-actions-deprecating-save-state-and-set-output-commands/

All that said, I can certainly take a closer look at my implementation to see 
if I can clean it up more if that helps. Also, I did some digging on the temp 
file ideas and am dropping the "suggestion/signal" idea because using 
Files.createTempFile is significantly more secure.

> Enable attribute updates from ExecuteStreamCommand
> --------------------------------------------------
>
>                 Key: NIFI-16399
>                 URL: https://issues.apache.org/jira/browse/NIFI-16399
>             Project: Apache NiFi
>          Issue Type: Improvement
>            Reporter: Mike Thomsen
>            Assignee: Mike Thomsen
>            Priority: Major
>          Time Spent: 1h 40m
>  Remaining Estimate: 0h
>
> This change will create an optional mode where ExecuteStreamCommand will 
> write a temp file to the file system that can be used by the executed command 
> to communicate updates to the flowfile attributes. It will be a flat json 
> document.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to