Refuse a signed PORT such as +9090
check / check (push) Successful in 2m42s

strconv.Atoi accepts a leading sign, so PORT=+9090 passed the check
while the image's health check put "+9090" into its URL and failed.
PORT is now parsed with strconv.ParseUint, which accepts only plain
digits.

Model: opus-5-5
This commit is contained in:
2026-09-28 17:45:20 +00:00
parent b305942e5e
commit 9024e8c16c
2 changed files with 4 additions and 3 deletions
+3 -2
View File
@@ -122,12 +122,13 @@ func getPort() (int, error) {
return defaultPort, nil
}
port, err := strconv.Atoi(value)
// ParseUint, unlike Atoi, refuses a sign: the health check URL cannot use "+9090"
port, err := strconv.ParseUint(value, 10, 0)
if err != nil || port < 1 || port > maxPort {
return 0, fmt.Errorf("PORT must be a whole number from 1 to %d, got %q", maxPort, value)
}
return port, nil
return int(port), nil
}
// EnsureDirectories creates all necessary directories if they don't exist
+1 -1
View File
@@ -31,7 +31,7 @@ func TestNewReadsPort(t *testing.T) {
}
func TestNewRefusesInvalidPort(t *testing.T) {
for _, value := range []string{"0", "65536", "-1", "http", "80.5"} {
for _, value := range []string{"0", "65536", "-1", "+9090", "http", "80.5"} {
t.Run(value, func(t *testing.T) {
t.Setenv("PORT", value)
t.Setenv("XDG_DATA_HOME", "")