Files
ROMFASTSQL/proxmox/lxc108-oracle/roa-windows-setup/scripts/04-create-synonyms-grants.ps1
Marius afb8266407 feat(oracle): granturi dictionar PACK_DIAG_SPATIU + sys-grants.sql legat in flux
Trei probleme gasite pregatind migrarea unui client de pe Oracle XE 11 pe XE 21c.

1. sys-grants.sql nu era rulat de niciun script PowerShell. Era referit doar din
   run-all-sys.sql, care se lanseaza manual. Pe orice instalare facuta cu
   RunAll.cmd lipseau sinonimele SYS (SYN_NEWSCHEMA, SYN_NEWSCHEMAJOB,
   EXECUTESCRIPTOS, SYN_PINFO), DMPDIR si granturile pe DBMS_SCHEDULER / UTL_* /
   DBMS_CRYPTO catre CONTAFIN_ORACLE. Legat ca STEP 3 in 04-create-synonyms-grants,
   dupa import - unde propriul header al fisierului spune ca trebuie rulat.

2. Granturile de dictionar cerute de PACK_DIAG_SPATIU lipseau complet. Consolidez
   sys_2026_08_03_05, sys_2026_08_03_07 si sys_2026_08_06_07 in sectiunea [5/5]
   din sys-grants.sql: SELECT direct pe 18 vederi dba_*/v$*, idempotent, cu
   ORA-00942 tratat pentru vederile absente pe alte editii/versiuni. Grantul prin
   rolul DBA nu ajunge - rolurile nu se aplica in pachetele cu drepturi de
   definitor, iar PACK_DIAG_SPATIU e exact asa; fara ele ramane INVALID si
   DIAGSPATIU_ZILNIC nu ruleaza.

3. Capcana la migrari: tabela de versiuni a lui PACK_MIGRARE traieste in
   CONTAFIN_ORACLE si vine cu DMP-ul, deci baza noua raporteaza scripturile sys_*
   drept aplicate si ROAACTUALIZARI le sare, desi in SYS nu exista nimic. De aceea
   obiectele si granturile SYS se pun la instalare, nu prin actualizator.
   Documentat in sys-updates/README.md si in ghidul nou.

07-verify-installation raporteaza nominal care dintre cele 18 granturi lipsesc.

Documentatie: docs/instalare-si-migrare-oracle.md - arbore de decizie intre
roa-windows-setup/ (client pe Windows), migration/ (Oracle in Docker pe LXC 108) si
new-roa-oracle-server/ (arhiva). Include de ce migration/ nu se foloseste la un
client Windows: creeaza PDB ROA cu OraclePass123, sinonime minimale, fara
SERVER_INFO / ROAUPDATE / ACL / sqlnet.ora, iar sys_objects.sql de acolo creeaza
INFO in SYSTEM - cauza cunoscuta a ORA-01653 la actualizare. Plus comenzile de
export din XE 11 / 10g si plafonul XE de 12 GB.

Corectat pe drum: dual-edition-test-plan si issues-se-prod indicau clonarea
VM 302 -> 303 pentru testul SE, dar 303 e ocupat de Win11-Adina. Mutat pe 304.

NETESTAT pe baza reala - VM 302 e oprit. Scripturile trec doar parse-check
PowerShell.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01SzF1hf4aFS1tmJWpPMiwGp
2026-08-25 15:46:28 +03:00

287 lines
10 KiB
PowerShell

#Requires -Version 5.1
<#
.SYNOPSIS
Create public synonyms and grants for ROA Oracle.
.DESCRIPTION
Creates public synonyms for CONTAFIN_ORACLE objects and configures:
- Public synonyms for tables, views, packages, types (via synonyms-public.sql)
- Public grants (SELECT, EXECUTE, REFERENCES) (via grants-public.sql)
- SYS grants, SYS public synonyms, DMPDIR and data dictionary reads
required by PACK_DIAG_SPATIU (via sys-grants.sql)
- SESIUNE context
- Network ACL for CONTAFIN_ORACLE
.PARAMETER OracleHome
Oracle home directory. If not specified, auto-detects.
.PARAMETER ServiceName
Database service name. Default: XEPDB1
.PARAMETER SystemPassword
SYSTEM user password. Default: romfastsoft
.PARAMETER SqlScriptsDir
Directory containing SQL scripts. Default: ..\sql
.EXAMPLE
.\04-create-synonyms-grants.ps1
.EXAMPLE
.\04-create-synonyms-grants.ps1 -ServiceName "ROA" -SystemPassword "mypassword"
.NOTES
File Name : 04-create-synonyms-grants.ps1
Prerequisite : Run 03-import-contafin.ps1 first
Copyright 2024 : ROMFAST
#>
[CmdletBinding()]
param(
[Parameter(Mandatory = $false)]
[string]$OracleHome,
[Parameter(Mandatory = $false)]
[string]$ServiceName = "XEPDB1",
[Parameter(Mandatory = $false)]
[string]$SystemPassword = "romfastsoft",
[Parameter(Mandatory = $false)]
[string]$SqlScriptsDir
)
$ErrorActionPreference = 'Stop'
# Source library functions
. "$PSScriptRoot\lib\logging-functions.ps1"
. "$PSScriptRoot\lib\oracle-functions.ps1"
# Initialize logging
$logPath = Join-Path $PSScriptRoot "..\logs\04-create-synonyms-grants_$(Get-Date -Format 'yyyyMMdd_HHmmss').log"
Initialize-LogFile -LogPath $logPath -ScriptName "04-create-synonyms-grants.ps1"
try {
Write-LogSection "Creating Public Synonyms and Grants"
# Validate Oracle installation
$oraHome = Get-OracleHome -OracleHome $OracleHome
Write-LogSuccess "Oracle Home: $oraHome"
# Determine SQL scripts directory
if (-not $SqlScriptsDir) {
$SqlScriptsDir = Join-Path $PSScriptRoot "..\sql"
}
# Verify SQL files exist
$synonymsScript = Join-Path $SqlScriptsDir "synonyms-public.sql"
$grantsScript = Join-Path $SqlScriptsDir "grants-public.sql"
$sysGrantsScript = Join-Path $SqlScriptsDir "sys-grants.sql"
if (-not (Test-Path -Path $synonymsScript)) {
throw "synonyms-public.sql not found at $synonymsScript"
}
if (-not (Test-Path -Path $grantsScript)) {
throw "grants-public.sql not found at $grantsScript"
}
if (-not (Test-Path -Path $sysGrantsScript)) {
throw "sys-grants.sql not found at $sysGrantsScript"
}
Write-Log "SQL scripts directory: $SqlScriptsDir"
# Test connection
Write-Log "Testing database connection..."
if (-not (Test-OracleConnection -OracleHome $oraHome -ServiceName $ServiceName `
-Password $SystemPassword)) {
throw "Cannot connect to database. Please verify ServiceName and SystemPassword."
}
Write-LogSuccess "Database connection successful"
# Verify CONTAFIN_ORACLE exists and has objects
Write-Log "Verifying CONTAFIN_ORACLE schema..."
$counts = Get-SchemaObjectCount -OracleHome $oraHome -ServiceName $ServiceName `
-Password $SystemPassword -SchemaName "CONTAFIN_ORACLE"
$totalObjects = if ($counts['TOTAL']) { $counts['TOTAL'] } else { 0 }
if ($totalObjects -eq 0) {
throw "CONTAFIN_ORACLE schema has no objects. Run 03-import-contafin.ps1 first."
}
Write-LogSuccess "CONTAFIN_ORACLE has $totalObjects objects"
# =========================================================================
# STEP 1: Create Public Synonyms (using synonyms-public.sql)
# =========================================================================
Write-LogSection "Creating Public Synonyms"
Write-Log "Running synonyms-public.sql..."
$result = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYS" -Password $SystemPassword -SqlFile $synonymsScript -AsSysdba
if ($result -match "synonym_count|SYNONYM_NAME") {
Write-LogSuccess "Public synonyms created successfully"
}
else {
Write-LogWarning "Could not verify synonym creation"
Write-LogDebug $result
}
# =========================================================================
# STEP 2: Create Grants and ACL (using grants-public.sql)
# =========================================================================
Write-LogSection "Creating Grants and Network ACL"
Write-Log "Running grants-public.sql..."
$grantsResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYS" -Password $SystemPassword -SqlFile $grantsScript -AsSysdba
if ($grantsResult -match "Grant|ACL|Grants Complete") {
Write-LogSuccess "Grants and ACL configured successfully"
}
else {
Write-LogWarning "Could not verify grants configuration"
Write-LogDebug $grantsResult
}
# =========================================================================
# STEP 3: SYS Grants, SYS Synonyms and Dictionary Reads (sys-grants.sql)
# =========================================================================
# Ruleaza dupa import: tabela de versiuni a lui PACK_MIGRARE traieste in
# CONTAFIN_ORACLE si vine cu DMP-ul, marcand scripturile sys_* drept aplicate.
# ROAACTUALIZARI nu le mai ruleaza pe baza noua, deci granturile catre SYS
# trebuie puse aici, la instalare.
Write-LogSection "Creating SYS Grants and Dictionary Reads"
Write-Log "Running sys-grants.sql..."
$sysGrantsResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYS" -Password $SystemPassword -SqlFile $sysGrantsScript -AsSysdba
if ($sysGrantsResult -match "SYS Grants and Synonyms Installation Complete") {
Write-LogSuccess "SYS grants, synonyms and dictionary reads configured"
}
else {
Write-LogWarning "Could not verify sys-grants.sql execution"
Write-LogDebug $sysGrantsResult
}
# =========================================================================
# STEP 4: Verify Results
# =========================================================================
Write-LogSection "Verifying Configuration"
# Count synonyms
$countSql = @"
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
SELECT 'SYNONYM_COUNT:' || COUNT(*)
FROM dba_synonyms
WHERE owner = 'PUBLIC'
AND table_owner = 'CONTAFIN_ORACLE';
EXIT;
"@
$countResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $countSql -Silent
$synonymCount = 0
if ($countResult -match "SYNONYM_COUNT:(\d+)") {
$synonymCount = [int]$Matches[1]
}
Write-Log "Public synonyms for CONTAFIN_ORACLE: $synonymCount"
# Verify SESIUNE context exists (created by grants-public.sql or synonyms-public.sql)
$contextSql = @"
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
SELECT 'CONTEXT_EXISTS:' || COUNT(*)
FROM dba_context
WHERE namespace = 'SESIUNE';
EXIT;
"@
$contextResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $contextSql -Silent
$contextExists = $false
if ($contextResult -match "CONTEXT_EXISTS:(\d+)") {
$contextExists = [int]$Matches[1] -gt 0
}
if ($contextExists) {
Write-LogSuccess "SESIUNE context exists"
}
else {
Write-LogWarning "SESIUNE context not found - creating..."
$createContextSql = @"
CREATE CONTEXT SESIUNE USING CONTAFIN_ORACLE.SET_VARIABILE;
EXIT;
"@
Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYS" -Password $SystemPassword -SqlCommand $createContextSql -AsSysdba
}
# Granturile de dictionar cerute de PACK_DIAG_SPATIU (sys-grants.sql [5/5])
$dictSql = @"
SET PAGESIZE 0 FEEDBACK OFF VERIFY OFF HEADING OFF ECHO OFF
SELECT 'DICT_GRANTS:' || COUNT(*)
FROM dba_tab_privs
WHERE grantee = 'CONTAFIN_ORACLE'
AND grantor = 'SYS'
AND privilege = 'SELECT'
AND table_name IN (
'DBA_DATA_FILES', 'DBA_FREE_SPACE', 'DBA_TEMP_FILES', 'DBA_SEGMENTS',
'DBA_TAB_STATS_HISTORY', 'DBA_SCHEDULER_JOB_RUN_DETAILS', 'DBA_RECYCLEBIN',
'V_`$INSTANCE', 'V_`$DATABASE', 'V_`$PARAMETER', 'V_`$TRANSACTION',
'V_`$TEMP_SPACE_HEADER', 'V_`$FLASH_RECOVERY_AREA_USAGE',
'DBA_TABLESPACES', 'V_`$VERSION',
'DBA_LOBS', 'DBA_LOB_PARTITIONS', 'DBA_INDEXES'
);
EXIT;
"@
$dictResult = Invoke-SqlPlus -OracleHome $oraHome -ServiceName $ServiceName `
-Username "SYSTEM" -Password $SystemPassword -SqlCommand $dictSql -Silent
$dictGrants = 0
if ($dictResult -match "DICT_GRANTS:(\d+)") {
$dictGrants = [int]$Matches[1]
}
if ($dictGrants -ge 15) {
Write-LogSuccess "Dictionary grants for PACK_DIAG_SPATIU: $dictGrants / 18"
}
else {
Write-LogWarning "Dictionary grants for PACK_DIAG_SPATIU: $dictGrants / 18 (asteptat minim 15)"
Write-LogWarning "Fara ele PACK_DIAG_SPATIU ramane INVALID si DIAGSPATIU_ZILNIC nu ruleaza."
Write-LogWarning "Verifica sectiunea [5/5] din sql\sys-grants.sql"
}
# =========================================================================
# Summary
# =========================================================================
Write-LogSection "Setup Complete"
Write-LogSuccess "Public synonyms and grants configured!"
Write-Log ""
Write-Log "Summary:"
Write-Log " SQL scripts used:"
Write-Log " - synonyms-public.sql (all public synonyms)"
Write-Log " - grants-public.sql (all grants and ACL)"
Write-Log " - sys-grants.sql (SYS grants, SYS synonyms, DMPDIR, dictionary reads)"
Write-Log " Public synonyms created: $synonymCount"
Write-Log " SESIUNE context: $(if ($contextExists) { 'Verified' } else { 'Created' })"
Write-Log " Network ACL: Configured (roaupdate.xml)"
Write-Log " Dictionary grants: $dictGrants / 18 (PACK_DIAG_SPATIU)"
Write-Log ""
Write-Log "Next steps:"
Write-Log " 1. Run 05-import-companies.ps1 to import company schemas"
Close-LogFile -Success $true
exit 0
}
catch {
Write-LogError "Setup failed: $_"
Write-LogError $_.ScriptStackTrace
Close-LogFile -Success $false
exit 1
}