Skip to content

l7policy: guard missing upstream addresses in response filter - #2064

Draft
veshant wants to merge 4 commits into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses
Draft

veshant wants to merge 4 commits into
cilium:mainfrom
veshant:fix-l7policy-null-upstream-addresses

Conversation

@veshant

@veshant veshant commented Oct 2, 2026

Copy link
Copy Markdown

A local HTTP reply can carry upstream info before an upstream socket has established local and remote addresses. When the reply includes Connection: close, AccessFilter::encodeHeaders() dereferences those addresses while comparing the upstream and downstream socket tuples, which can crash Envoy.

Guard that comparison until all four addresses are present. The existing downstream-drain behavior remains for matching socket tuples. Add regression cases for missing upstream addresses (both or either one), matching addresses, and nonmatching addresses.

Fixes #2063.

Validation: clang-format 18.1.8 passed with --dry-run --Werror, and git diff --check passed. The C++ unit test could not be run locally because Docker BuildKit storage became read-only before compilation; CI should confirm compilation and behavior.

Skip the same-tuple connection-close comparison when a local response has upstream information without established socket addresses.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Exercise absent upstream socket addresses and preserve connection draining for matching tuples.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
Signed-off-by: Veshant Chettiar <veshantc@gmail.com>
veshant added a commit to veshant/cilium-proxy that referenced this pull request Oct 2, 2026
Carry the source fix from cilium#2064 onto the exact proxy revision pinned by Cilium 1.20.2 for isolated image testing.

Signed-off-by: Veshant Chettiar <veshantc@gmail.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

l7policy: guard null upstream socket addresses when encoding local replies

1 participant