mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-07-26 11:49:16 +00:00
fix(git-sources): harden webhook delivery, transport errors, and clone limits (#1249)
* fix(git-sources): harden webhook delivery, transport errors, and clone limits Map webhook-pull outcomes to real HTTP status codes (200 success, 202 debounced, 404 no source, 422 failure) instead of always returning 200, so a Git provider and any monitoring on it can tell when a delivery actually failed. Close a concurrent webhook fan-out gap: the debounce window is now re-checked inside the per-stack lock, so simultaneous deliveries for one push run a single clone instead of one per request. The whole pull/apply critical section runs under a single lock acquisition. Unwrap fetch transport causes (ENOTFOUND, ECONNREFUSED, ECONNRESET, TLS) so a clone failure surfaces an actionable, host-qualified message instead of a bare "fetch failed". Cap how many bytes a single clone may download to protect the host disk; operators can tune it with GITSOURCE_MAX_CLONE_BYTES (default 100 MB). Log webhook pull failures server-side, since the webhook path is unattended. * test(git-sources): assert surfaced host via toContain to satisfy CodeQL * fix(git-sources): bound per-file read, treat debounced webhooks as non-failure, correct clone-cap docs * docs(git-sources): correct clone-cap comment to describe a download bound, not disk
This commit is contained in:
@@ -126,3 +126,10 @@ SENCHO_EXPERIMENTAL=false
|
||||
# enable idle teardown after that many ms of zero active mesh streams;
|
||||
# the next mesh dial re-opens it. Default 0 (persistent).
|
||||
SENCHO_MESH_PROXY_TUNNEL_IDLE_MS=0
|
||||
|
||||
# Maximum bytes a single Git Source clone may download from the Git host before
|
||||
# it is aborted. This bounds network transfer and abuse, not the decompressed
|
||||
# on-disk size. A shallow clone of a compose repo is tiny; raise this only if
|
||||
# you track compose files in a legitimately large repository. Default
|
||||
# 104857600 (100 MB).
|
||||
GITSOURCE_MAX_CLONE_BYTES=104857600
|
||||
|
||||
Reference in New Issue
Block a user