Repository navigation
Conversation
Stale ftw-tests-schema/v3 entry left behind by a previous dependency change. Pre-existing on main; the go-mod-tidy hook fails without this. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
A YAML block scalar (`|`) silently appends a trailing newline to a header value. Header.Write wrote header name/value pairs straight onto the wire with no validation, so a value like this broke the request's header framing without any error, causing the request to be misinterpreted by the target while go-ftw reported success. Reject header names and values containing a raw CR or LF instead, pointing at encoded_request/encoded_data as the way to send control characters intentionally. Fixes #662 Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (5)
🔗 Linked repositories identifiedCodeRabbit considers these linked repositories for cross-repo context during reviews:
💤 Files with no reviewable changes (1)
Included review availability: Your plan provides up to 2 included reviews per hour; 0 remain after this review. 📝 WalkthroughWalkthroughChanges
CRLF Header Validation
Priority: ➖ Normal Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Medium Suggested labels: Merge Risk: ⚪ Minimal · up to The CR/LF validation change has no remaining supported merge-blocking risk in the reviewed request path. 🚥 Pre-merge checks | ✅ 16 | ❌ 2❌ Failed checks (2 warnings)
✅ Passed checks (16 passed)
Full details: Out of Scope Changes checkExplanation The Full details: Ai Contribution DisclosureExplanation The PR violates the disclosure policy. The supplied PR body has no Resolution Add a lowercase
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
defer cleanLogs(logLines) was registered after the test loop, so it only ran when Run() completed normally. Any early return from the loop (e.g. a fatal RunStage error) skipped it, leaking the log file watcher. On Windows this held the log file open and made the CI job's TempDir cleanup fail with "process cannot access the file". The new TestHeaderCRLFInjectionRun test is the first in this suite to make Run() return an error from inside the loop, which is what surfaced this. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Summary
Header.Writewrote header name/value pairs straight onto the wire with no validation. A header value containing a raw CR or LF — for example from an unquoted YAML block scalar (|), which silently appends a trailing newline — broke the request's header framing without producing any error.Header.Writenow rejects header names/values containing a raw CR or LF, pointing atencoded_request/encoded_dataas the documented way to send control characters intentionally (that path bypassesHeader.Writeentirely and is unaffected).Run()'sdefer cleanLogs(logLines)was registered after the test loop, so any early-return error from inside the loop (which the new regression test is the first in the suite to trigger) skipped cleanup and leaked the log-file watcher. On Windows this held the log file open and broke the test'sTempDircleanup in CI.go.mod/go.sumtidy (staleftw-tests-schema/v3entry) needed to satisfy thego-mod-tidypre-commit hook, split into its own commit.Fixes #662
Test plan
TestWriteRejectsCRLFInValue/TestWriteRejectsCRLFInNameinftwhttp/header_test.gorunner/testdata/TestHeaderCRLFInjectionRun.yaml+TestHeaderCRLFInjectionRuninrunner/run_test.go) reproducing the exact header from the issue and assertingRun()now surfaces a clear error instead of trivially passinggo test ./...passesgolangci-lint runreports 0 issues