Skip to content

[v1.31.x] Validate both token readings in internal callback namespace check - #12382

Open
davidporter-id-au wants to merge 2 commits into
temporalio:release/v1.31.xfrom
davidporter-id-au:cp-11876-followup-v1.31
Open

davidporter-id-au wants to merge 2 commits into
temporalio:release/v1.31.xfrom
davidporter-id-au:cp-11876-followup-v1.31

Conversation

@davidporter-id-au

Copy link
Copy Markdown
Contributor

What

Follow-up to #11876 / #12319 on release/v1.31.x.

The internal-callback token can be read two ways: as a bare ChasmComponentRef, or as a NexusOperationCompletion envelope wrapping a ref. History's consumption path (chasm_invocation.go) always acts on the bare-ref reading. The validator added in #12319 picked one reading (envelope if it parsed cleanly, else bare) and checked only that one.

This change validates every reading the token's bytes can produce instead of picking one, rejecting if any targets a different namespace, so the namespace check always agrees with what history will actually use.

Why?

Keeps the validator's view of "what namespace does this token target" consistent with what the rest of the system does with the same bytes.

How did you test it?

  • Added unit test: a token crafted to read differently as a bare ref vs. an envelope
  • go build ./service/frontend/...
  • go test -tags test_dep ./service/frontend/...

Rollback

Nothing is persisted, so rolling back is safe.

🤖 Generated with Claude Code

A bare ChasmComponentRef and a NexusOperationCompletion envelope share
a wire type on field 6 (component_path vs. component_ref), so a bare
ref can be crafted to also decode as an envelope wrapping a different
ref. The validator was picking one reading and checking only that one,
while history (chasm_invocation.go) always acts on the bare reading --
so validation and consumption could disagree on which ref a token
actually refers to.

Validate every reading the token's bytes can produce instead of
picking one, rejecting if any targets a different namespace.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
@davidporter-id-au
davidporter-id-au requested review from a team as code owners October 3, 2026 20:15
@github-actions

github-actions Bot commented Oct 3, 2026 •

Copy link
Copy Markdown
Contributor

Claude finished @davidporter-id-au's task in 1m 48s —— View job


Reviewed 2 files, 0 findings.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant