Repository navigation
fix: log the full request target in Rust audit and unlink the socket when chown fails (#55) - #72
Merged
Merged
Conversation
This was referenced Oct 11, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Part of #55 (Task 4 of the plan: the Rust audit
uriand the socket left behind after a failed chown).What changes
uriis the raw request target (path plus query, escapes kept), for allowed and denied requests. It used to be the path only, so?force=1or?all=1was missing from the audit trail. Go (r.RequestURI) and TS (req.url) already logged the full target; routing still uses the path alone.bind_unix_listenerleft the freshly bound socket on disk (mode0600) when setting its group or mode failed. Go (l.Close()) and TS (server.close()) already removed it. The chown and chmod steps move intoset_socket_ownership_and_mode; on error, Rust drops the listener, removes the file (ignoring a removal error), and returns the unchanged error.TestHandlerAuditURIIsRequestTarget/test_handler_audit_uri_is_request_target/ "logs the raw request target as the audit uri":GET /containers/json?all=1(ALLOW) andDELETE /containers/a%2Fb?force=1(DENY); asserts the exacturiand decision of each line.Review notes
bump=patch tag=v0.3.5.AGENTS.md/README.mdare updated in Task 6, as planned.Verification
56540e6(tests, no fix): Rust failed both new assertions, Go and TS passed (pinning their existing behaviour):make test-all: Go ok (109 tests), Rust147 passed, TS164 tests, 0 fail, 1 skipped.make lint-allpasses. Rust integration:ALL 45 TESTS PASSED.Type of change
Implementation(s) changed
Testing
make test-all)make test-integration-rs: 45; Go and TS code unchanged, CI runs all three)Checklist