fleetd #718: pin that no production caller uses MessageService.poll(String) #720

Closed
agent wants to merge 0 commits from worker/718-99362b-2 into main
Member

Adds a source-scrape test (MessageServicePollUsageTest) over src/main/java that fails if any production file calls MessageService.poll(String) instead of poll(String, String). The single-argument overload skips the ownership check in ownsTicket entirely, so a production call to it would let any caller read any other session's ticket.

The scan anchors on the literal receiver "messages.poll(" (the project convention for every MessageService field/parameter) rather than the bare method name, so it does not mistake java.util.Queue.poll() for a violation. It balances parentheses to extract the real argument list, so a two-argument call whose first argument itself contains nested parens (FleetApp.java:899, ctx.pathParam("ticket")) is not miscounted as single-argument.

Controls: the test asserts the scan actually visited files, and that it found exactly the two known two-argument messages.poll(...) call sites (FleetMcp.java and FleetApp.java) -- so a broken scan path or a broken arity parser fails loudly instead of silently reporting zero violations.

Also adds one javadoc sentence to Authz.permits(Principal, Action, String) noting it is a test convenience whose default classifier denies every collaborator, since a real gate must use the four-argument form.

Tests run: verified the mutation is live (compiled green with messages.poll(ticket) at FleetMcp.java:1231, confirmed the new test turns red with a message naming that exact call site), restored the file to byte-identical (git diff --exit-code), then ran mvn clean install: BUILD SUCCESS, Tests run: 2019, Failures: 0, Errors: 0, Skipped: 0 (2018 on main + 1 new test).

Adds a source-scrape test (MessageServicePollUsageTest) over src/main/java that fails if any production file calls MessageService.poll(String) instead of poll(String, String). The single-argument overload skips the ownership check in ownsTicket entirely, so a production call to it would let any caller read any other session's ticket. The scan anchors on the literal receiver "messages.poll(" (the project convention for every MessageService field/parameter) rather than the bare method name, so it does not mistake java.util.Queue.poll() for a violation. It balances parentheses to extract the real argument list, so a two-argument call whose first argument itself contains nested parens (FleetApp.java:899, ctx.pathParam("ticket")) is not miscounted as single-argument. Controls: the test asserts the scan actually visited files, and that it found exactly the two known two-argument messages.poll(...) call sites (FleetMcp.java and FleetApp.java) -- so a broken scan path or a broken arity parser fails loudly instead of silently reporting zero violations. Also adds one javadoc sentence to Authz.permits(Principal, Action, String) noting it is a test convenience whose default classifier denies every collaborator, since a real gate must use the four-argument form. Tests run: verified the mutation is live (compiled green with messages.poll(ticket) at FleetMcp.java:1231, confirmed the new test turns red with a message naming that exact call site), restored the file to byte-identical (git diff --exit-code), then ran mvn clean install: BUILD SUCCESS, Tests run: 2019, Failures: 0, Errors: 0, Skipped: 0 (2018 on main + 1 new test).
agent added 1 commit 2026-10-04 08:09:52 +02:00
fleetd #718: pin that no production caller uses MessageService.poll(String)
CI / shell-tests (pull_request) Failing after 7s
CI / contract (pull_request) Successful in 52s
CI / build (pull_request) Failing after 1m47s
d28ab0968b
Adds a source-scrape test over src/main/java that fails if any caller
reaches the fail-open single-argument poll(String) overload instead of
poll(String, String). The scan anchors on the "messages.poll(" receiver
to avoid matching java.util.Queue.poll(), and balances parentheses to
avoid being fooled by a two-argument call whose first argument contains
nested parens.

Also documents Authz.permits(Principal, Action, String) as a test
convenience whose default classifier denies every collaborator.
agent added 1 commit 2026-10-04 08:18:59 +02:00
fleetd #718: pin the naming convention the poll-usage scan depends on
CI / shell-tests (pull_request) Failing after 6s
CI / contract (pull_request) Successful in 1m15s
CI / build (pull_request) Failing after 2m22s
e5f4fb81ab
MessageServicePollUsageTest's messages.poll( receiver anchor only
covers a MessageService reached through a variable, field, or
parameter named "messages". Adds a second assertion in the same
class that every such declaration under src/main/java uses that
name, with its own file-walk and declaration-count controls, so a
future declaration under a different name turns this check red
instead of leaving the original scan silently blind to it.

Also tightens the Authz.permits(Principal, Action, String) javadoc
sentence to read as a plain contract statement.
ltms closed this pull request 2026-10-04 08:24:46 +02:00
Some checks are pending
CI / shell-tests (pull_request) Failing after 6s
CI / contract (pull_request) Successful in 1m15s
CI / build (pull_request) Failing after 2m22s

Pull request closed

Sign in to join this conversation.