Skip to content

l7policy: guard missing upstream addresses in response filter - #2064

Open
veshant wants to merge 1 commit into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses
Open

veshant wants to merge 1 commit into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses

Conversation

@veshant

@veshant veshant commented Oct 2, 2026

Copy link
Copy Markdown

A local HTTP reply can carry upstream info before an upstream socket has established local and remote addresses. When the reply includes Connection: close, AccessFilter::encodeHeaders() dereferences those addresses while comparing the upstream and downstream socket tuples, which can crash Envoy.

Guard that comparison until all four addresses are present. The existing downstream-drain behavior remains for matching socket tuples. Add regression cases for missing upstream addresses (both or either one), matching addresses, and nonmatching addresses.

Fixes #2063.

Validation: clang-format 18.1.8 passed with --dry-run --Werror, and git diff --check passed. The C++ unit test could not be run locally because Docker BuildKit storage became read-only before compilation; CI should confirm compilation and behavior.

veshant added a commit to veshant/cilium-proxy that referenced this pull request Oct 2, 2026
Carry the source fix from cilium#2064 onto the exact proxy revision pinned by Cilium 1.20.2 for isolated image testing.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
@veshant
veshant marked this pull request as ready for review October 5, 2026 05:48
@veshant
veshant requested a review from a team as a code owner October 5, 2026 05:48
@veshant
veshant requested review from mhofstetter and a balanced review from Copilot October 5, 2026 05:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@jrajahalme jrajahalme left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution :-) Please squash commits into one, we do not do that automatically on merge and the commit-to-commit churn is not needed in the git history. I'll have a 2nd look when that is done.

@jrajahalme
jrajahalme removed the request for review from mhofstetter October 7, 2026 15:20
Skip the same-tuple connection-close comparison when a local response has upstream information without established socket addresses. Cover missing and matching addresses in the L7 policy test.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
@veshant
veshant force-pushed the fix-l7policy-null-upstream-addresses branch from 065b690 to 29fa635 Compare October 9, 2026 21:21
@veshant

veshant commented Oct 9, 2026

Copy link
Copy Markdown
Author

@jrajahalme Thanks for the review. I’ve squashed the PR to one signed-off commit (29fa635) on current main and added the direct includes flagged by clang-tidy. The new format and integration workflows are awaiting maintainer approval, so this head has not been validated by CI yet. Could you take another look once those checks run?

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

l7policy: guard null upstream socket addresses when encoding local replies

3 participants