package cloud import ( "context" "time" "github.com/safedep/dry/log" "github.com/safedep/pmg/config" "github.com/safedep/pmg/internal/analytics" "github.com/safedep/pmg/internal/audit" "github.com/safedep/pmg/internal/ui" "github.com/safedep/pmg/usefulerror" "github.com/spf13/cobra" ) // manualSyncLockTimeout caps how long `pmg cloud sync` waits to acquire the // shared sync lock when an auto-sync child is already running. Long enough to // let a normal background drain complete, short enough that a stuck process // surfaces as a usefulerror rather than an indefinite hang. const manualSyncLockTimeout = 30 * time.Second var syncTimeout time.Duration func newSyncCommand() *cobra.Command { cmd := &cobra.Command{ Use: "sync", Short: "Sync pending audit events to SafeDep Cloud", RunE: runSync, } cmd.Flags().DurationVar(&syncTimeout, "timeout", 15*time.Minute, "Maximum time to spend syncing events") return cmd } func runSync(cmd *cobra.Command, args []string) error { cfg := config.Get() if analytics.IsDisabled() { ui.Infof("Cloud sync is disabled because telemetry is disabled (disable_telemetry or PMG_DISABLE_TELEMETRY)") return nil } if !cfg.Config.Cloud.Enabled { ui.ErrorExit(usefulerror.Useful(). WithCode(usefulerror.ErrCodeLifecycle). WithHumanError("Cloud sync is not enabled"). WithHelp("Set 'cloud.enabled: true' in PMG config to enable cloud sync")) } lock := audit.NewSyncLock(cfg.CloudSyncLockPath()) lockCtx, lockCancel := context.WithTimeout(cmd.Context(), manualSyncLockTimeout) defer lockCancel() locked, err := lock.TryLockContext(lockCtx, 250*time.Millisecond) if err != nil { ui.ErrorExit(usefulerror.Useful(). Wrap(err). WithCode(usefulerror.ErrCodeLifecycle). WithHumanError("Failed to acquire cloud sync lock"). WithHelp("Another sync may be in progress; try again shortly")) } if !locked { ui.ErrorExit(usefulerror.Useful(). WithCode(usefulerror.ErrCodeLifecycle). WithHumanError("Another cloud sync is already in progress"). WithHelp("Wait for the in-progress sync to finish, then try again")) } defer func() { if err := lock.Unlock(); err != nil { log.Warnf("failed to release cloud sync lock: %v", err) } }() ctx, cancel := context.WithTimeout(cmd.Context(), syncTimeout) defer cancel() bundle, err := audit.NewSyncClientBundle(cfg) if err != nil { ui.ErrorExit(usefulerror.Useful(). Wrap(err). WithCode(usefulerror.ErrCodeLifecycle). WithHumanError("Failed to initialize cloud sync client"). WithHelp("Run 'pmg cloud login' to store credentials, or set SAFEDEP_API_KEY and SAFEDEP_TENANT_ID environment variables")) } defer func() { if err := bundle.Close(); err != nil { log.Warnf("failed to close sync client: %v", err) } }() synced, err := bundle.Sync(ctx) recordLastSyncAttempt(cfg) if err != nil { ui.ErrorExit(usefulerror.Useful(). Wrap(err). WithCode(usefulerror.ErrCodeNetwork). WithHumanError("Failed to sync events to SafeDep Cloud"). WithHelp("Check your network connectivity and ensure SafeDep Cloud is reachable"). WithAdditionalHelp("Override the cloud endpoint with SAFEDEP_CLOUD_DATA_ADDR if needed")) } ui.Successf("Synced %d events to SafeDep Cloud", synced) return nil }