Conversation
benrkia
force-pushed
the
ilbe/proxy-bypass
branch
from
September 21, 2026 16:49
dce7e8d to
8c303d9
Compare
The Runtime API client used Net::HTTP.post and Net::HTTP.new(host, port), both of which default to :ENV proxy resolution and honor HTTP(S)_PROXY. A customer-configured proxy then routed calls to the API endpoint through the proxy, so a proxy in the environment could break function init and result delivery even though it should never affect communication with the API. Route the invocation poll and the three write-backs through a single client built with a nil proxy argument, which disables Net::HTTP's default proxy resolution so the link-local API endpoint is never proxied.
benrkia
force-pushed
the
ilbe/proxy-bypass
branch
from
September 21, 2026 17:03
8c303d9 to
80e418d
Compare
Adds a handler that asks the fixed RapidClient#build_client for an HTTP client bound to a non-loopback URI while HTTP_PROXY is set, and returns the resulting proxy? values. Suite asserts that a bare Net::HTTP.new picks up the proxy and RapidClient does not. On unfixed code build_client does not exist, the handler raises NoMethodError and the suite fails.
maxday
self-requested a review
September 22, 2026 09:00
The earlier commit introspected RapidClient#build_client directly, which overlapped with the unit tests already added in PR #68. Per review feedback, replace it with a customer-shaped test: bind RIE Runtime API to the container's own non-loopback hostname (so Ruby's URI.find_proxy does not silently bypass the proxy for loopback), set HTTP_PROXY on the image to an unreachable address, and have the handler simply return "success". With the fix the RIC bypasses HTTP_PROXY and the handler runs; without it the RIC tries the unreachable proxy for next_invocation and every suite in the image fails.
Reviewer flagged that setting HTTP_PROXY globally in Dockerfile.test made every suite exercise the fix, so proxy.json no longer proved anything the other suites did not, and a regression would break the whole matrix instead of the one intended test. Move the proxy setup into a second image (Dockerfile.test.proxy) that extends local/test with HTTP_PROXY and the custom entrypoint, and move the proxy suite under test/dockerized/suites/proxy/ so the default suites/*.json glob no longer picks it up. Workflow now builds both images and runs each glob against its own image.
test: add dockerized regression test for the proxy-bypass fix
maxday
approved these changes
Sep 23, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description of changes:
The Runtime API client used Net::HTTP.post and Net::HTTP.new(host, port), both of which default to :ENV proxy resolution and honor HTTP(S)_PROXY. A customer-configured proxy then routed calls to the API endpoint through the proxy, so a proxy in the environment could break function init and result delivery even though it should never affect communication with the API.
Route the invocation poll and the three write-backs through a single client built with a nil proxy argument, which disables Net::HTTP's default proxy resolution so the link-local API endpoint is never proxied.
Target (OCI, Managed Runtime, both):
Both
By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.