Core Lock

Locking mechanism that prevents concurrent execution of different tasks

Utilities · Cortex Lock

Details

IDCore Lock
ProviderPalo Alto Networks
CategoryUtilities
From Version5.0.0
Supported ModulesAgentix Cortex Cloud Cloud Runtime Security Cloud Posture Security XSIAM EDR

README

Overview

Core Lock is a mechanism that enables users to prevent concurrent execution of tasks. This is a native integration, which does not require configuration.


Commands

You can execute these commands from the Cortex XSOAR CLI, as part of an automation, or in a playbook. After you successfully execute a command, a DBot message appears in the War Room with the command details.

  1. Get a lock: lock-get
  2. Show lock information: lock-info
  3. Release a lock: lock-release
  4. Release all locks: lock-release-all

Get a lock

Gets a specific lock. If the lock doesn't exist, it creates one. If the lock is already in use, the command waits until the lock is released or until timeout is reached. If timeout is reached and the lock hasn't been released, the command fails to get the lock.

Base Command

lock-get

Input
Parameter Description
name Lock name. When omitted, the default is Default.
info Additional information about the lock
timeout Timeout to wait for the lock to be released

Show lock information

Retreives information for a specified lock.

Base Command

lock-info

Input
Parameter Description
name Name of lock to retrieve information for. When omitted, the default is Default.

Release a lock

Release a specified lock.

Base Command

lock-release

Input
Parameter Description
name Name of lock to release. When omitted, the default is Default.

Release all locks

Release a specified lock.

Base Command

lock-release-all

Input

There is no input for this command.

Troubleshooting

If you use multiple locks which might be set in parallel, it is recommended to enable the Sync integration cache (Available from Cortex XSOAR 6.2.0).

Configuration parameters

  • timeout — Default timeout (seconds) for wait on locks to be released (required)
  • sync — Sync integration cache

Commands (8)

  • core-lock-get

    Gets a specific lock. If the lock doesn't exist, it creates one. If the lock is already in use, the command waits until the lock is released or until timeout is reached. If timeout is reached and the lock hasn't been released, the command fails to get the lock.

  • core-lock-info

    Show information on locks

  • core-lock-release

    Release a lock

  • core-lock-release-all

    Release all locks

  • demisto-lock-get

    Gets a specific lock. If the lock doesn't exist, it creates one. If the lock is already in use, the command waits until the lock is released or until timeout is reached. If timeout is reached and the lock hasn't been released, the command fails to get the lock.

  • demisto-lock-info

    Show information on locks

  • demisto-lock-release

    Release a lock

  • demisto-lock-release-all

    Release all locks

function guid() {
  function s4() {
    return Math.floor((1 + Math.random()) * 0x10000)
      .toString(16)
      .substring(1);
  }
  return s4() + s4() + '-' + s4() + '-' + s4() + '-' + s4() + '-' + s4() + s4() + s4();
}
var sync = params.sync;
function setLock(guid, info, version) {
    if (sync) {
        mergeVersionedIntegrationContext({newContext : {[lockName] : {guid: guid, info: info}}, version : version});
    } else {
        var integrationContext = getIntegrationContext() || {};
        integrationContext[lockName] = {guid: guid, info: info};
        setIntegrationContext(integrationContext);
    }
} function getLock() {
    if (sync) {
        var versionedIntegrationContext = getVersionedIntegrationContext(true, true) || {};
        var integrationContext = versionedIntegrationContext.context;
        if (!integrationContext[lockName]) {
            integrationContext[lockName] = {};
        }
        return [integrationContext[lockName], versionedIntegrationContext.version];
    } else {
        var integrationContext = getIntegrationContext() || {};
        if (!integrationContext[lockName]) {
            integrationContext[lockName] = {};
        }
        return [integrationContext[lockName], null];
    }
}
var lockName = args.name || 'Default';

switch (command) {
    case 'test-module':
        return 'ok';

    case 'demisto-lock-get':
    case 'core-lock-get':
        var lockTimeout = args.timeout || params.timeout || 600;
        var lockInfo = 'Locked by incident #' + incidents[0].id + '.';
        lockInfo += (args.info) ? ' Additional info: ' + args.info :'';

        var guid = guid();
        var time = 0;
        var lock, version;

        do{
            [lock, version] = getLock();
            if (lock.guid === guid) {
                break;
            }
            if (!lock.guid) {
                try {
                    setLock(guid, lockInfo, version);
                } catch(err) {
                    logDebug(err.message)
                }
            }
            wait(1);
        } while (time++ < lockTimeout) ;

        [lock, version] = getLock();

        if (lock.guid === guid) {
            var md = '### Core Locking Mechanism\n';
            md += 'Lock acquired successfully\n';
            md += 'GUID: ' + guid;
            return { ContentsFormat: formats.markdown, Type: entryTypes.note, Contents: md } ;
        } else {
            var md = 'Timeout waiting for lock\n';
            md += 'Lock name: ' + lockName + '\n';
            md += 'Lock info: ' + lock.info + '\n';
            return { ContentsFormat: formats.text, Type: entryTypes.error, Contents: md };
        }
        break;

    case 'demisto-lock-release':
    case 'core-lock-release':
        if(sync)   {
            mergeVersionedIntegrationContext({newContext : {[lockName] : 'remove'}, retries : 5});
        } else {
            integrationContext = getVersionedIntegrationContext(sync);
            delete integrationContext[lockName];
            setVersionedIntegrationContext(integrationContext, sync);
        }

        var md = '### Core Locking Mechanism\n';
        md += 'Lock released successfully';
        return { ContentsFormat: formats.markdown, Type: entryTypes.note, Contents: md } ;

    case 'demisto-lock-release-all':
    case 'core-lock-release-all':
        setVersionedIntegrationContext({}, sync);

        var md = '### Core Locking Mechanism\n';
        md += 'All locks released successfully';
        return { ContentsFormat: formats.markdown, Type: entryTypes.note, Contents: md } ;

    case 'demisto-lock-info':
    case 'core-lock-info':
        integrationContext = getVersionedIntegrationContext(sync);
        var obj = [];

        var res;
        var md = '### Core Locking Mechanism\n';
        var locks = (lockName === 'Default') ? Object.keys(integrationContext) : [lockName];

        locks.forEach(function(lock){
            md += 'Lock name: ' + lock + ' - ';
            if (integrationContext[lock] && integrationContext[lock].guid) {
                md += 'Locked.\n';
                md += '- GUID: ' + integrationContext[lock].guid + '\n';
                md += '- Info: ' + integrationContext[lock].info + '\n\n';
                obj.push({lock: lock, state: integrationContext[lock]});
            } else {
                md += 'Not locked\n\n';
            }

        });
        return { ContentsFormat: formats.json, Type: entryTypes.note, Contents: obj, HumanReadable: md } ;

    default:
        var md = 'Unknown command ' + command;
        return { ContentsFormat: formats.text, Type: entryTypes.error, Contents: md };
}