Skip to content

test(gateway): reject ambiguous singleton responses - #446

Merged
seonghobae merged 5 commits into
test/440-gateway-header-mediation-redfrom
test/440-gateway-response-singleton-red
Sep 24, 2026
Merged

seonghobae merged 5 commits into
test/440-gateway-header-mediation-redfrom
test/440-gateway-response-singleton-red

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 22, 2026 •

Copy link
Copy Markdown
Contributor

Refs #440. Test-only child of #441; #441 remains the sole production gateway-mediation writer.

Fresh review found that Wardnet rejected duplicate response Content-Type but admitted repeated Location and Retry-After. RFC 9110 §10.2.2 defines Location = URI-reference and warns that multiple Location field lines are invalid/non-interoperable; §10.2.3 defines Retry-After = HTTP-date / delay-seconds. WWW-Authenticate and bounded x-wardnet-app-meta remain intentionally repeatable where their contracts allow it.

This branch changes only tests/gateway_response_singleton_mediation.rs: two real loopback buyer-path hostile cases require duplicate upstream Location or Retry-After to fail closed as 502 Bad Gateway without relaying the ambiguous field.

RED correction and root cause

Hosted predecessor a6869e8b2fb1e3c6b9eb6e7d893950693297e864 established the duplicate Retry-After RED directly. Its duplicate-Location case, however, used 302 Found. On current repaired parent #441 exact 29a35163fc5bab860f247a68a6b1d5f797d73182, hosted CI 35893328787, rust job 107290948038, proved why that Location witness was confounded rather than a valid mediation RED: formatting and 151 library tests passed, the repaired duplicate Retry-After case passed, but the 302 Location case returned 404 after reqwest followed the upstream redirect before admit_response_headers() could inspect the original duplicate field set. That 404 is redirect behavior, not evidence that the repaired mediation policy relayed an ambiguous 302.

The same hosted run also proves the parent unit policy rejects duplicate content-type, location, and retry-after; the remaining question is real buyer-path wiring for Location without redirect interception.

Exact child b8b5804b655a424967252d8ac22172eb4a1338fb therefore repairs only the hostile fixture: duplicate Location is now returned on the protocol-valid 201 Created path, which exercises Location response metadata without triggering reqwest redirect handling. The production source remains byte-identical in this child. Fresh exact-head CI must execute this isolated witness before GREEN is claimed.

The automatic-redirect observation is a separate outbound-authority integration gap, not a reason to copy redirect/DNS/TLS policy into Wardnet. Exact evidence has been handed to canonical EgressWeave Rust-consumer issue #237; Wardnet must consume an immutable released EgressWeave boundary rather than implement a second transport authority.

Parent repair

The minimum Wardnet-owned production mediation repair remains only in parent #441 at 29a35163fc5bab860f247a68a6b1d5f797d73182: admit_response_headers() rejects duplicate Location and Retry-After alongside duplicate Content-Type, with an owned unit contract covering all three singletons. No transport/egress/quarantine/orchestrator/appguardrail logic was copied.

This child previously adopted that exact parent through ordinary two-parent merge; its effective child delta remains one hostile regression-test file. Do not claim GREEN or merge this child until the unchanged current exact head executes successfully. Parent #441 exact-head CI/Fuzz must also be terminal GREEN on the same repair lineage.

No production repair in this child; no EgressWeave transport logic, streaming/backpressure work, Coraza implementation, central workflow copy, mutable foreign dependency, force update, destructive rebase, self/model approval, gate weakening, synthetic status or routine bypass.

@coderabbitai

coderabbitai Bot commented Sep 22, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Auto reviews are disabled on base/target branches other than the default branch.

Please check the settings in the CodeRabbit UI or the .coderabbit.yaml file in this repository. To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Advanced

Run ID: 96f943a4-f879-4e5c-8125-72b8ca15f8ab

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Fresh exact-current execution update: CI 35732508565 / rust job 106761365593 finally acquired hosted ubuntu-24.04 runner 1002090997 and completed at 2026-09-22T16:23:34Z. It did not reach the singleton-response tests. cargo fmt --check failed only in four inherited Coraza fixtures (tests/coraza_loopback_proxy_boundary.rs, coraza_non_disruptive_detection.rs, coraza_non_utf8_body.rs, coraza_proven_engine_adapter.rs) because this child is intentionally still based on historical #441 7a769e57...; the emitted rustfmt delta is exactly the formatting already repaired on current Coraza parent #435 11e7fab....

Therefore this run is parent/base-format evidence, not semantic RED for duplicate Location/Retry-After, and it does not authorize production singleton changes. Keep this child test-only and parked while current #441 7f1c7ca... still carries the exact-parent-guarded temporary synthesis helper. After #441 settles onto a normal source head, non-force adopt that complete parent here and reacquire exact-head CI; only an executed hostile singleton failure may be handed to #441 as causal RED. No force/rebase, no child production repair, no predecessor-result promotion.

@seonghobae
seonghobae marked this pull request as ready for review September 24, 2026 01:06
@seonghobae
seonghobae merged commit bac6df0 into test/440-gateway-header-mediation-red Sep 24, 2026
3 checks passed
@seonghobae
seonghobae deleted the test/440-gateway-response-singleton-red branch September 24, 2026 01:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant