Skip to content

fix: assorted small validation and robustness fixes#2450

Open
andrewwhitecdw wants to merge 3 commits into
NVIDIA:mainfrom
andrewwhitecdw:fix-assorted-validation-robustness/aw
Open

fix: assorted small validation and robustness fixes#2450
andrewwhitecdw wants to merge 3 commits into
NVIDIA:mainfrom
andrewwhitecdw:fix-assorted-validation-robustness/aw

Conversation

@andrewwhitecdw

Copy link
Copy Markdown

Summary

Three small, independent robustness fixes found during code review, one commit each:

  1. server: Kubernetes label key/value validation used Unicode-aware is_alphanumeric(), so labels like café or 日本語 passed gateway validation but would be rejected by the Kubernetes API server (the label spec is ASCII-only). The same functions already validate the key prefix with ASCII-only checks.
  2. cli: print_policy_revision_table truncated server-supplied load_error strings at a fixed byte index (&rev.load_error[..40]), panicking when the index lands inside a multi-byte UTF-8 character (same bug class as fix(cli): avoid panic on multi-byte UTF-8 in --since duration #2446).
  3. sandbox: the ephemeral-port advisory check used port > 49152, omitting port 49152 itself from the IANA dynamic/private range (49152–65535 inclusive).

This PR supersedes #2410, which was auto-closed by the vouch-check workflow before I was vouched.

Related Issue

N/A — small fixes found during code review.

Changes

  • validate_label_key/validate_label_value: use is_ascii_alphanumeric(); added Unicode rejection tests
  • print_policy_revision_table: back off to a char boundary when truncating load_error
  • mechanistic_mapper: port >= 49152 for the ephemeral range note

Testing

  • mise run pre-commit passes (mise unavailable in this environment; ran equivalent cargo fmt + cargo clippy on all touched crates — clean)
  • Unit tests added/updated (cargo test -p openshell-server validate_label — 40 passed, incl. 2 new)
  • E2E tests added/updated (if applicable)

Checklist

  • Follows Conventional Commits
  • Commits are signed off (DCO)
  • Architecture docs updated (if applicable)

validate_label_key and validate_label_value used Unicode-aware
char::is_alphanumeric(), so values like 'café' or '日本語' passed
gateway validation even though the Kubernetes label spec
(([A-Za-z0-9][-A-Za-z0-9_.]*)?[A-Za-z0-9])? is ASCII-only and the
API server rejects such labels later. The same functions already
validate the key prefix with ASCII-only checks.

Use is_ascii_alphanumeric() and add regression tests for Unicode
keys and values.

Signed-off-by: Andrew White <andrewh@cdw.com>
Two display paths in sandbox policy commands sliced server-supplied
strings without guarding:

- sandbox_policy_set used &resp.policy_hash[..12] unconditionally;
  an empty or short proto3 hash field would panic. Use the existing
  short_hash() helper, as nearby call sites already do.
- The policy revision table truncated load_error at a fixed byte
  index (&rev.load_error[..40]), panicking on multi-byte UTF-8 in
  server error messages. Back off to a char boundary instead.

Signed-off-by: Andrew White <andrewh@cdw.com>
The IANA dynamic/private (ephemeral) port range is 49152-65535
inclusive, but the check used port > 49152, silently omitting the
advisory note for port 49152 itself.

Signed-off-by: Andrew White <andrewh@cdw.com>
@copy-pr-bot

copy-pr-bot Bot commented Jul 23, 2026

Copy link
Copy Markdown

This pull request requires additional validation before any workflows can run on NVIDIA's runners.

Pull request vetters can view their responsibilities here.

Contributors can view more details about this message here.

@andrewwhitecdw

Copy link
Copy Markdown
Author

I have read the DCO document and I hereby sign the DCO.

@github-actions

github-actions Bot commented Jul 23, 2026

Copy link
Copy Markdown

All contributors have signed the DCO ✍️ ✅
Posted by the DCO Assistant Lite bot.

@johntmyers johntmyers left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

PR Review Status

Validation: This is project-valid small, concentrated robustness work. PR #2410 is the same author's auto-closed predecessor, not competing active work.
Head SHA: 949b5b6be5d0634296691cf826d0c81e4f48c7f1

Review findings:

  • Two warning-level UTF-8 panic paths remain in CLI rendering; see the inline comments.
  • Suggested coverage: exercise a multibyte load_error crossing byte 40 and the ephemeral-port boundary at 49151/49152.

Docs: Fern docs and navigation are not needed because these fixes add no command, option, workflow, or documented contract.

Next state: gator:in-review; author changes are needed before pipeline/E2E gating.

"·".dimmed(),
resp.version,
&resp.policy_hash[..12]
short_hash(&resp.policy_hash)

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

Warning: short_hash still uses &hash[..12], so a server response such as aaaaaaaaaaaé panics when byte 12 splits a UTF-8 character (CWE-248). Make short_hash select the twelfth character boundary using char_indices() and add short/multibyte regression cases; that fixes both new call sites.

};
let error_short = if rev.load_error.len() > 40 {
format!("{}...", &rev.load_error[..40])
// Back off to a char boundary: byte-index slicing panics on

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

gator-agent

Warning: The revision table still byte-slices the server-supplied policy hash, preserving the same UTF-8 panic (CWE-248). After fixing short_hash, replace this branch with let hash_short = short_hash(&rev.policy_hash);.

@johntmyers johntmyers added the gator:in-review Gator is reviewing or awaiting PR review feedback label Jul 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

gator:in-review Gator is reviewing or awaiting PR review feedback

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants