A null body limit is refused, not read as no limit; the gate on the wrong machine is refused
Review of the registry hand-over. The proxy's bodyLimit treated an absent key and a JSON null alike, so a `max-request-body: null` was served unlimited here while the adapter skipped it and the catalogue refused it — one provider carrying what the others refuse. Presence is now checked before the value is read. The catalogue-backed test asserted the gate pulling the store in beside it as the feature. It was the fault: a node-scoped requirement with one candidate installs that candidate, so a gate assigned to a machine without the store raised a second, empty one there behind the real credentials and the public name. The store's seat is one per mesh now (mesh-catalog), and the test asserts the refusal by name. Delete is asserted only behind the lock. hq ADR 0082/0104, the registry hand-over.
This commit is contained in:
@@ -387,12 +387,17 @@ func routesFrom(path string) (map[string]route, error) {
|
||||
// A limit it cannot honour is a route it does not serve — skipped and named, like a
|
||||
// port that is not one. Serving the route with no limit instead would carry exactly what
|
||||
// the module said not to carry, and report success.
|
||||
limit, ok := bodyLimit(c.Values["max-request-body"])
|
||||
if !ok {
|
||||
log.Printf("%s on %s asked for route %q with a max-request-body of %v, which is not "+
|
||||
"a whole positive number of bytes; skipped", c.From, c.Node, name,
|
||||
c.Values["max-request-body"])
|
||||
continue
|
||||
// Absent is no limit; present is a limit or a refusal — a `null` written where a number
|
||||
// was meant is the second, not the first, and the adapter and the catalogue read it the
|
||||
// same way.
|
||||
var limit int64
|
||||
if raw, said := c.Values["max-request-body"]; said {
|
||||
var ok bool
|
||||
if limit, ok = bodyLimit(raw); !ok {
|
||||
log.Printf("%s on %s asked for route %q with a max-request-body of %v, which is "+
|
||||
"not a whole positive number of bytes; skipped", c.From, c.Node, name, raw)
|
||||
continue
|
||||
}
|
||||
}
|
||||
// Where the mesh says that machine is. Empty means it is this one — a workload beside the
|
||||
// proxy is ordinary, and reaching it over loopback is both correct and the only thing
|
||||
@@ -409,13 +414,11 @@ func routesFrom(path string) (map[string]route, error) {
|
||||
return out, nil
|
||||
}
|
||||
|
||||
// bodyLimit reads a contribution's `max-request-body`: absent is no limit, and anything present
|
||||
// must be a whole positive number of bytes — the same rule the control plane's catalogue applies
|
||||
// when it parses the manifest, so a limit that reaches here has already passed it once.
|
||||
// bodyLimit reads a contribution's `max-request-body`, which must be a whole positive number of
|
||||
// bytes — the same rule the control plane's catalogue applies when it parses the manifest, so a
|
||||
// limit that reaches here has already passed it once. Absence is the caller's to notice; a `null`
|
||||
// arriving here is refused like any other non-number.
|
||||
func bodyLimit(v any) (int64, bool) {
|
||||
if v == nil {
|
||||
return 0, true
|
||||
}
|
||||
var n float64
|
||||
switch x := v.(type) {
|
||||
case float64:
|
||||
|
||||
Reference in New Issue
Block a user