Refuse invalid settings at start, health check follows PORT (closes #31) #32

Merged
clawbot merged 2 commits from issue-31-upaas into next 2026-09-28 20:08:42 +02:00
Collaborator

Implements #31 per the brief in its comments.

  • PORT (a whole number from 1 to 65535) and XDG_DATA_HOME (an absolute path) are checked when the configuration is built, before the database opens. A bad value stops the start with an error and a non-zero exit. Before, a bad PORT left the daemon running without HTTP, and a relative XDG_DATA_HOME put the database somewhere else.
  • entrypoint.sh refuses a MALLOC_ARENA_MAX that is not a positive whole number, because glibc ignores a bad one silently.
  • A malformed GOMEMLIMIT already stops the start (the Go runtime refuses it); nothing added.
  • The HEALTHCHECK probes the port PORT names, 8080 when unset.
  • README: Configuration lists XDG_DATA_HOME, gives the real Linux state directory and says an invalid value stops the start; a new "Running under upaas" section follows Memory.

Worth knowing:

  • PORT is now read in internal/config instead of internal/server, so server.New takes the config; its two test callers changed with it.
  • The XDG_DATA_HOME check also runs as root, where the value is otherwise ignored, so the refusal does not depend on the user.

Disclosures:

  • Unverified: the 5g memory limit could not be exercised on the build host; Docker there refuses --memory (the cgroup is in threaded mode).
  • Judgement call: an empty value counts as unset for all three checks, as PORT and XDG_DATA_HOME already did; the README says so.
  • Not changed: the README's macOS state directory line is also wrong (routewatch instead of berlin.sneak.app.routewatch); outside the brief.

Model: opus-5-5

Implements https://git.eeqj.de/sneak/routewatch/issues/31 per the brief in its comments. - `PORT` (a whole number from 1 to 65535) and `XDG_DATA_HOME` (an absolute path) are checked when the configuration is built, before the database opens. A bad value stops the start with an error and a non-zero exit. Before, a bad `PORT` left the daemon running without HTTP, and a relative `XDG_DATA_HOME` put the database somewhere else. - `entrypoint.sh` refuses a `MALLOC_ARENA_MAX` that is not a positive whole number, because glibc ignores a bad one silently. - A malformed `GOMEMLIMIT` already stops the start (the Go runtime refuses it); nothing added. - The `HEALTHCHECK` probes the port `PORT` names, 8080 when unset. - README: Configuration lists `XDG_DATA_HOME`, gives the real Linux state directory and says an invalid value stops the start; a new "Running under upaas" section follows Memory. Worth knowing: - `PORT` is now read in `internal/config` instead of `internal/server`, so `server.New` takes the config; its two test callers changed with it. - The `XDG_DATA_HOME` check also runs as root, where the value is otherwise ignored, so the refusal does not depend on the user. Disclosures: - Unverified: the `5g` memory limit could not be exercised on the build host; Docker there refuses `--memory` (the cgroup is in threaded mode). - Judgement call: an empty value counts as unset for all three checks, as `PORT` and `XDG_DATA_HOME` already did; the README says so. - Not changed: the README's macOS state directory line is also wrong (`routewatch` instead of `berlin.sneak.app.routewatch`); outside the brief. Model: opus-5-5
clawbot added the needs-review label 2026-09-28 19:11:01 +02:00
clawbot self-assigned this 2026-09-28 19:11:01 +02:00
clawbot added 1 commit 2026-09-28 19:11:01 +02:00
PORT (1 to 65535) and XDG_DATA_HOME (an absolute path) are now checked in
the config package, which is built before the database opens, so a bad
value stops the start with an error and a non-zero exit instead of leaving
the daemon running without HTTP or putting the database somewhere else.
entrypoint.sh refuses a MALLOC_ARENA_MAX that is not a positive whole
number, since glibc ignores a bad one silently. The HEALTHCHECK probes the
port PORT names. The README corrects the Linux state directory, lists
XDG_DATA_HOME, and adds a "Running under upaas" section.

Model: opus-5-5
Author
Collaborator
  • internal/config/config.go line 125: strconv.Atoi accepts a leading plus sign, so PORT=+9090 passes the check and the daemon serves on port 9090, but the image's HEALTHCHECK puts the value into the URL as given, curl refuses localhost:+9090, and the container turns unhealthy. Under upaas that deploy fails 60 seconds later with nothing in the log pointing at PORT, where it should have stopped the start. Acceptable: accept only plain digits from 1 to 65535 (for example strconv.ParseUint(value, 10, 16), which refuses any sign, plus the zero check), and add +9090 to the refused values in TestNewRefusesInvalidPort (internal/config/config_test.go line 34).

Model: opus-5-5

- `internal/config/config.go` line 125: `strconv.Atoi` accepts a leading plus sign, so `PORT=+9090` passes the check and the daemon serves on port 9090, but the image's `HEALTHCHECK` puts the value into the URL as given, curl refuses `localhost:+9090`, and the container turns `unhealthy`. Under upaas that deploy fails 60 seconds later with nothing in the log pointing at `PORT`, where it should have stopped the start. Acceptable: accept only plain digits from 1 to 65535 (for example `strconv.ParseUint(value, 10, 16)`, which refuses any sign, plus the zero check), and add `+9090` to the refused values in `TestNewRefusesInvalidPort` (`internal/config/config_test.go` line 34). Model: opus-5-5
clawbot added needs-rework and removed needs-review labels 2026-09-28 19:33:02 +02:00
clawbot added 1 commit 2026-09-28 19:45:26 +02:00
Refuse a signed PORT such as +9090
check / check (push) Successful in 2m42s
9024e8c16c
strconv.Atoi accepts a leading sign, so PORT=+9090 passed the check
while the image's health check put "+9090" into its URL and failed.
PORT is now parsed with strconv.ParseUint, which accepts only plain
digits.

Model: opus-5-5
Author
Collaborator

For #32 (comment): PORT is now read with strconv.ParseUint, which accepts only plain digits, so PORT=+9090 stops the start; +9090 is added to the refused values in TestNewRefusesInvalidPort.

Model: opus-5-5

For https://git.eeqj.de/sneak/routewatch/pulls/32#issuecomment-103995: `PORT` is now read with `strconv.ParseUint`, which accepts only plain digits, so `PORT=+9090` stops the start; `+9090` is added to the refused values in `TestNewRefusesInvalidPort`. Model: opus-5-5
clawbot added needs-review and removed needs-rework labels 2026-09-28 19:46:00 +02:00
Author
Collaborator

Review passed.

Model: opus-5-5

Review passed. Model: opus-5-5
clawbot removed the needs-review label 2026-09-28 20:04:33 +02:00
clawbot merged commit f2a9e90625 into next 2026-09-28 20:08:42 +02:00
clawbot deleted branch issue-31-upaas 2026-09-28 20:08:43 +02:00
Sign in to join this conversation.
No Reviewers
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: sneak/routewatch#32