Skip to content

fix(ima): 三处游标分页补重复游标防护与跳数上限 - #3889

Open
linus-liu-web wants to merge 1 commit into
Tencent:mainfrom
linus-liu-web:fix/ima-pagination-guards
Open

linus-liu-web wants to merge 1 commit into
Tencent:mainfrom
linus-liu-web:fix/ima-pagination-guards

Conversation

@linus-liu-web

Copy link
Copy Markdown
Contributor

改动

  • ListResources / search 回退 / ListAllKBFiles 三条循环只以 IsEnd || NextCursor == "" 终止,重复游标下 0.5 秒发出 10006 次请求仍不返回。
  • 复用同族 connector(钉钉 / Confluence / 飞书)的写法:重复游标立即报错 + 跳数上限 + 触顶 Warn。
  • 注:这条缺陷此前已在我们已合并的 fix(feishu): 云盘分页补上 #3645 给 wiki 加的重复 page token 防护 #3770 正文「已知边界」里公开披露(ima/connector.go:84/101/360),本 PR 把它补上,不再另开 issue。

@linus-liu-web
linus-liu-web force-pushed the fix/ima-pagination-guards branch 3 times, most recently from bfd1127 to c7d5f7c Compare September 29, 2026 15:01
ListResources 的两条循环(get_addable_knowledge_base_list、search_knowledge_base
兜底)与 listAllKBFiles 的 get_knowledge_list 循环都只以 is_end / 空 next_cursor
为终止条件:既不记录用过的游标,也没有跳数上限。厂商只要回 is_end=false 且
next_cursor 不前进,循环就会一直请求同一页,bases / out 随迭代重复增长,直到任务
deadline —— 资源选择器接口不返回,同步任务永远不进终态。

同族的 DingTalk(seenTokens + maxPages)、Confluence(seen +
maxPaginationHops)、飞书(seenPageTokens)都已有守卫,本包漏了。

改动:
- 抽一条 nextPageCursor:每页取回 next_cursor 后调用,重复游标立即返回错误(不再
  重试),页数达到 maxPaginationHops(10000,对齐 Confluence)时 Warn 并报错。
  触顶必须留日志:从外部看这种失败和"还在正常同步"一模一样。
- 三条循环按同一写法接入;listAllKBFiles 的守卫错误补上 get_knowledge_list 前缀。
- 假 IMA 服务器支持覆盖某个 action 的分页字段(固定游标 / 每次换新游标 / 有限页数 /
  每次换 payload / 请求预算),并给"无防护时会空转"的场景设请求上限,使回归用例失
  败而不是挂死。

新增用例:三条循环的重复游标(都在第 2 次请求即报错)、跳数上限(正好 10000 次
请求后报错且日志含 "pagination exceeded 10000 pages")、真实多页仍正常合并。
去掉本次改动后这四条用例全部失败(重复游标场景实测跑到 10006 次请求才被假服务器
的预算拦下)。
@linus-liu-web
linus-liu-web force-pushed the fix/ima-pagination-guards branch from c7d5f7c to 62eddef Compare September 30, 2026 08:18

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant