A null body limit is refused, not read as no limit; the gate on the wrong machine is refused

Review of the registry hand-over. The proxy's bodyLimit treated an absent key and a JSON
null alike, so a `max-request-body: null` was served unlimited here while the adapter
skipped it and the catalogue refused it — one provider carrying what the others refuse.
Presence is now checked before the value is read.

The catalogue-backed test asserted the gate pulling the store in beside it as the feature.
It was the fault: a node-scoped requirement with one candidate installs that candidate, so
a gate assigned to a machine without the store raised a second, empty one there behind the
real credentials and the public name. The store's seat is one per mesh now (mesh-catalog),
and the test asserts the refusal by name. Delete is asserted only behind the lock.

hq ADR 0082/0104, the registry hand-over.
This commit is contained in:
2026-09-23 23:35:29 +02:00
parent 01d57b629f
commit b48572bdfc
3 changed files with 53 additions and 25 deletions
+15 -12
View File
@@ -387,12 +387,17 @@ func routesFrom(path string) (map[string]route, error) {
// A limit it cannot honour is a route it does not serve — skipped and named, like a
// port that is not one. Serving the route with no limit instead would carry exactly what
// the module said not to carry, and report success.
limit, ok := bodyLimit(c.Values["max-request-body"])
if !ok {
log.Printf("%s on %s asked for route %q with a max-request-body of %v, which is not "+
"a whole positive number of bytes; skipped", c.From, c.Node, name,
c.Values["max-request-body"])
continue
// Absent is no limit; present is a limit or a refusal — a `null` written where a number
// was meant is the second, not the first, and the adapter and the catalogue read it the
// same way.
var limit int64
if raw, said := c.Values["max-request-body"]; said {
var ok bool
if limit, ok = bodyLimit(raw); !ok {
log.Printf("%s on %s asked for route %q with a max-request-body of %v, which is "+
"not a whole positive number of bytes; skipped", c.From, c.Node, name, raw)
continue
}
}
// Where the mesh says that machine is. Empty means it is this one — a workload beside the
// proxy is ordinary, and reaching it over loopback is both correct and the only thing
@@ -409,13 +414,11 @@ func routesFrom(path string) (map[string]route, error) {
return out, nil
}
// bodyLimit reads a contribution's `max-request-body`: absent is no limit, and anything present
// must be a whole positive number of bytes — the same rule the control plane's catalogue applies
// when it parses the manifest, so a limit that reaches here has already passed it once.
// bodyLimit reads a contribution's `max-request-body`, which must be a whole positive number of
// bytes — the same rule the control plane's catalogue applies when it parses the manifest, so a
// limit that reaches here has already passed it once. Absence is the caller's to notice; a `null`
// arriving here is refused like any other non-number.
func bodyLimit(v any) (int64, bool) {
if v == nil {
return 0, true
}
var n float64
switch x := v.(type) {
case float64:
+5 -2
View File
@@ -208,7 +208,8 @@ func TestABodyLimitIsReadFromTheContributionOrTheRouteIsSkipped(t *testing.T) {
{"from":"gate","node":"anchor","values":{"name":"registry-api.example","port":5001,"max-request-body":21474836480}},
{"from":"app","node":"anchor","values":{"name":"app.example","port":8080}},
{"from":"odd","node":"anchor","values":{"name":"odd.example","port":8081,"max-request-body":"20g"}},
{"from":"none","node":"anchor","values":{"name":"none.example","port":8082,"max-request-body":0}}
{"from":"none","node":"anchor","values":{"name":"none.example","port":8082,"max-request-body":0}},
{"from":"nul","node":"anchor","values":{"name":"nul.example","port":8083,"max-request-body":null}}
]}`))
if err != nil {
t.Fatal(err)
@@ -219,7 +220,9 @@ func TestABodyLimitIsReadFromTheContributionOrTheRouteIsSkipped(t *testing.T) {
if got := routes["app.example"].MaxRequestBody; got != 0 {
t.Errorf("a route that asked for no limit was given one: %d", got)
}
for _, skipped := range []string{"odd.example", "none.example"} {
// A `null` is not absence: the adapter skips it and the catalogue refuses it, and a proxy
// that read it as "no limit" would be the one provider carrying what the others refuse.
for _, skipped := range []string{"odd.example", "none.example", "nul.example"} {
if _, served := routes[skipped]; served {
t.Errorf("%s asked for a limit that is not a number of bytes and was served anyway", skipped)
}