Copilot commented on code in PR #13383:
URL: https://github.com/apache/trafficserver/pull/13383#discussion_r3582744075


##########
include/ts/ts.h:
##########
@@ -1585,10 +1585,19 @@ TSReturnCode           TSHttpSsnClientFdGet(TSHttpSsn 
ssnp, int *fdp);
 /* TS-1008 END */
 
 /** Change packet firewall mark for the client side connection
- *
-    @note The change takes effect immediately
 
-    @return TS_SUCCESS if the client connection was modified
+    Sets the entire client-side packet firewall mark to @a mark; the whole 
mark is replaced. @a mark
+    is interpreted as a 32-bit unsigned bit pattern.
+
+    @note The firewall mark is only honored on platforms whose OS supports it, 
specifically Linux via
+    @c SO_MARK. On platforms without @c SO_MARK support the call still returns 
TS_SUCCESS when a
+    client connection is present, but setting the mark has no effect at the OS 
layer (it is a safe
+    no-op).

Review Comment:
   The API docs imply the mark is applied at the OS layer whenever the platform 
supports SO_MARK, but the implementation only calls setsockopt(SO_MARK) when 
the connection’s sockopt_flags include SOCK_OPT_PACKET_MARK (bit 0x10 from 
proxy.config.net.sock_option_flag_in). Without that flag, 
TSHttpTxnClientPacketMarkSet will return TS_SUCCESS (when a client VC exists) 
but won’t actually change the socket mark.
   
   Evidence: TSHttpTxnClientPacketMarkSet only sets vc->options.packet_mark and 
calls vc->apply_options() (src/api/InkAPI.cc:4898-4900). 
Connection::apply_options gates SO_MARK on (opt.sockopt_flags & 
SOCK_OPT_PACKET_MARK) (src/iocore/net/UnixConnection.cc:294-299).



##########
doc/developer-guide/api/functions/TSHttpTxnClientPacketMarkSet.en.rst:
##########
@@ -32,11 +32,24 @@ Synopsis
 Description
 ===========
 
-Change packet firewall :arg:`mark` for the client side connection.
+Change the packet firewall :arg:`mark` for the client side connection. The
+entire firewall mark is replaced with :arg:`mark`, which is interpreted as a
+32-bit unsigned bit pattern.
+
+Returns :const:`TS_SUCCESS` when the client connection was modified, and
+:const:`TS_ERROR` when there is no client connection to modify.
+
+.. note::
+
+   The firewall mark is only honored on platforms whose OS supports it,
+   specifically Linux via ``SO_MARK``. On platforms without ``SO_MARK`` support
+   the call still returns :const:`TS_SUCCESS` when a client connection is
+   present, but setting the mark has no effect at the OS layer (it is a safe
+   no-op).

Review Comment:
   This doc currently states the mark is applied immediately (on SO_MARK 
platforms), but the implementation only applies SO_MARK when the inbound socket 
option flags include PACKET_MARK (0x10 from 
proxy.config.net.sock_option_flag_in). Otherwise TSHttpTxnClientPacketMarkSet 
still returns TS_SUCCESS (when a client VC exists) but won’t actually change 
the socket mark.
   
   Evidence: src/api/InkAPI.cc:4898-4900 sets packet_mark then calls 
apply_options(); src/iocore/net/UnixConnection.cc:294-299 gates SO_MARK on 
opt.sockopt_flags & SOCK_OPT_PACKET_MARK.



##########
tests/gold_tests/pluginTest/client_packet_mark/client_packet_mark.test.py:
##########
@@ -0,0 +1,103 @@
+#  Licensed to the Apache Software Foundation (ASF) under one
+#  or more contributor license agreements.  See the NOTICE file
+#  distributed with this work for additional information
+#  regarding copyright ownership.  The ASF licenses this file
+#  to you under the Apache License, Version 2.0 (the
+#  "License"); you may not use this file except in compliance
+#  with the License.  You may obtain a copy of the License at
+#
+#      http://www.apache.org/licenses/LICENSE-2.0
+#
+#  Unless required by applicable law or agreed to in writing, software
+#  distributed under the License is distributed on an "AS IS" BASIS,
+#  WITHOUT WARRANTIES OR CONDITIONS OF ANY KIND, either express or implied.
+#  See the License for the specific language governing permissions and
+#  limitations under the License.
+
+import os
+import socket
+
+Test.Summary = '''
+Verify TSHttpTxnClientPacketMarkSet sets the client-side firewall mark to the
+supplied value, using a test plugin that reads the applied mark back off the
+client socket.
+'''
+
+
+def _can_set_so_mark() -> bool:
+    """Probe whether SO_MARK can actually be set on this host.
+
+    Setting SO_MARK is Linux-only and requires CAP_NET_ADMIN or CAP_NET_RAW.
+    On any host that lacks the capability (or the platform), setsockopt raises,
+    and the applied value would be unobservable -- so the test is skipped
+    rather than failed.
+    """
+    if not hasattr(socket, "SO_MARK"):
+        return False
+    try:
+        with socket.socket(socket.AF_INET, socket.SOCK_STREAM) as probe:
+            probe.setsockopt(socket.SOL_SOCKET, socket.SO_MARK, 0x1)
+        return True
+    except (OSError, PermissionError):
+        return False
+
+
+Test.SkipUnless(
+    Condition.IsPlatform("linux"),
+    Condition(_can_set_so_mark, "Setting SO_MARK requires Linux with 
CAP_NET_ADMIN or CAP_NET_RAW", True),
+)
+
+
+class ClientPacketMarkTest:
+    """Drive TSHttpTxnClientPacketMarkSet through a test plugin and assert on 
the
+    firewall mark read back off the client socket.
+
+    The starting mark is seeded per process via
+    proxy.config.net.sock_packet_mark_in, applied at accept time.
+    """
+
+    # Value the plugin sets; the mark is expected to become exactly this.
+    SET_MARK = 0x0000000A
+
+    def __init__(self):
+        self._server = self._make_server()
+        self._ts = self._make_ats("ts", seed_mark=0x0000FF00)
+
+    def _make_server(self) -> 'Process':
+        server = Test.MakeOriginServer("server")
+        request_header = {"headers": "GET / HTTP/1.1\r\nHost: 
example.com\r\n\r\n", "timestamp": "1469733493.993", "body": ""}
+        response_header = {"headers": "HTTP/1.1 200 OK\r\nConnection: 
close\r\n\r\n", "timestamp": "1469733493.993", "body": ""}
+        server.addResponse("sessionlog.json", request_header, response_header)
+        return server
+
+    def _make_ats(self, name: str, seed_mark: int) -> 'Process':
+        ts = Test.MakeATSProcess(name, enable_cache=False)
+        ts.Disk.records_config.update(
+            {
+                'proxy.config.net.sock_packet_mark_in': seed_mark,
+                'proxy.config.net.sock_option_flag_in': 0x11,
+                'proxy.config.diags.debug.enabled': 1,

Review Comment:
   0x11 is an opaque bitmask value in the test config. Since this test depends 
on PACKET_MARK being enabled (0x10) to actually apply SO_MARK, it’d help 
readability to express the mask as a bitwise OR (and/or add a short comment) 
rather than a magic number.



-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: [email protected]

For queries about this service, please contact Infrastructure at:
[email protected]

Reply via email to