Skip to content

l7policy: guard missing upstream addresses in response filter - #2064

Open
veshant wants to merge 5 commits into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses
Open

veshant wants to merge 5 commits into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses

Conversation

@veshant

@veshant veshant commented Oct 2, 2026

Copy link
Copy Markdown

A local HTTP reply can carry upstream info before an upstream socket has established local and remote addresses. When the reply includes Connection: close, AccessFilter::encodeHeaders() dereferences those addresses while comparing the upstream and downstream socket tuples, which can crash Envoy.

Guard that comparison until all four addresses are present. The existing downstream-drain behavior remains for matching socket tuples. Add regression cases for missing upstream addresses (both or either one), matching addresses, and nonmatching addresses.

Fixes #2063.

Validation: clang-format 18.1.8 passed with --dry-run --Werror, and git diff --check passed. The C++ unit test could not be run locally because Docker BuildKit storage became read-only before compilation; CI should confirm compilation and behavior.

veshant added a commit to veshant/cilium-proxy that referenced this pull request Oct 2, 2026
Carry the source fix from cilium#2064 onto the exact proxy revision pinned by Cilium 1.20.2 for isolated image testing.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
@veshant
veshant marked this pull request as ready for review October 5, 2026 05:48
@veshant
veshant requested a review from a team as a code owner October 5, 2026 05:48
@veshant
veshant requested review from mhofstetter and a balanced review from Copilot October 5, 2026 05:48

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Skip the same-tuple connection-close comparison when a local response has upstream information without established socket addresses.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Exercise absent upstream socket addresses and preserve connection draining for matching tuples.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
@veshant
veshant force-pushed the fix-l7policy-null-upstream-addresses branch from a895e9d to 065b690 Compare October 7, 2026 00:13

@jrajahalme jrajahalme left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thanks for your contribution :-) Please squash commits into one, we do not do that automatically on merge and the commit-to-commit churn is not needed in the git history. I'll have a 2nd look when that is done.

@jrajahalme
jrajahalme removed the request for review from mhofstetter October 7, 2026 15:20

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

l7policy: guard null upstream socket addresses when encoding local replies

3 participants