test(gateway): reject ambiguous singleton responses - #446
seonghobae merged 5 commits into
Conversation
|
Important Review skippedAuto reviews are disabled on base/target branches other than the default branch. Please check the settings in the CodeRabbit UI or the ⚙️ Run configurationConfiguration used: Organization UI Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Fresh exact-current execution update: CI Therefore this run is parent/base-format evidence, not semantic RED for duplicate |
bac6df0
into
test/440-gateway-header-mediation-red
Refs #440. Test-only child of #441; #441 remains the sole production gateway-mediation writer.
Fresh review found that Wardnet rejected duplicate response
Content-Typebut admitted repeatedLocationandRetry-After. RFC 9110 §10.2.2 definesLocation = URI-referenceand warns that multiple Location field lines are invalid/non-interoperable; §10.2.3 definesRetry-After = HTTP-date / delay-seconds.WWW-Authenticateand boundedx-wardnet-app-metaremain intentionally repeatable where their contracts allow it.This branch changes only
tests/gateway_response_singleton_mediation.rs: two real loopback buyer-path hostile cases require duplicate upstreamLocationorRetry-Afterto fail closed as502 Bad Gatewaywithout relaying the ambiguous field.RED correction and root cause
Hosted predecessor
a6869e8b2fb1e3c6b9eb6e7d893950693297e864established the duplicateRetry-AfterRED directly. Its duplicate-Locationcase, however, used302 Found. On current repaired parent #441 exact29a35163fc5bab860f247a68a6b1d5f797d73182, hosted CI35893328787, rust job107290948038, proved why that Location witness was confounded rather than a valid mediation RED: formatting and 151 library tests passed, the repaired duplicateRetry-Aftercase passed, but the 302 Location case returned404after reqwest followed the upstream redirect beforeadmit_response_headers()could inspect the original duplicate field set. That 404 is redirect behavior, not evidence that the repaired mediation policy relayed an ambiguous 302.The same hosted run also proves the parent unit policy rejects duplicate
content-type,location, andretry-after; the remaining question is real buyer-path wiring for Location without redirect interception.Exact child
b8b5804b655a424967252d8ac22172eb4a1338fbtherefore repairs only the hostile fixture: duplicate Location is now returned on the protocol-valid201 Createdpath, which exercises Location response metadata without triggering reqwest redirect handling. The production source remains byte-identical in this child. Fresh exact-head CI must execute this isolated witness before GREEN is claimed.The automatic-redirect observation is a separate outbound-authority integration gap, not a reason to copy redirect/DNS/TLS policy into Wardnet. Exact evidence has been handed to canonical EgressWeave Rust-consumer issue #237; Wardnet must consume an immutable released EgressWeave boundary rather than implement a second transport authority.
Parent repair
The minimum Wardnet-owned production mediation repair remains only in parent #441 at
29a35163fc5bab860f247a68a6b1d5f797d73182:admit_response_headers()rejects duplicateLocationandRetry-Afteralongside duplicateContent-Type, with an owned unit contract covering all three singletons. No transport/egress/quarantine/orchestrator/appguardrail logic was copied.This child previously adopted that exact parent through ordinary two-parent merge; its effective child delta remains one hostile regression-test file. Do not claim GREEN or merge this child until the unchanged current exact head executes successfully. Parent #441 exact-head CI/Fuzz must also be terminal GREEN on the same repair lineage.
No production repair in this child; no EgressWeave transport logic, streaming/backpressure work, Coraza implementation, central workflow copy, mutable foreign dependency, force update, destructive rebase, self/model approval, gate weakening, synthetic status or routine bypass.