The GitHub Actions job "Scalafmt" on pekko.git/no-includes-in-join-config has 
failed.
Run started by GitHub user pjfanning (triggered by pjfanning).

Head commit for run:
cdf1e6338afdcb9c209d56aa80cefe870380cce2 / PJ Fanning 
<[email protected]>
fix: don't resolve HOCON includes in config that arrived in a message

Motivation:
Three sites parse HOCON that came off the wire with the default parse
options: InternalClusterAction.InitJoin and InitJoinAck in
ClusterMessageSerializer, and the Config payload in MiscMessageSerializer.
HOCON include directives are resolved by the parser rather than by
resolve(), so include file(...) and include classpath(...) read from the
local filesystem and classpath and include url(...) performs an outbound
request, all while deserializing a peer's message. InitJoin is accepted
from a node that has not joined, in ClusterDaemon's uninitialized state.

Modification:
Add WireConfig (@InternalApi), which parses with a ConfigIncluder that
resolves every include to an empty object, and route the three sites
through it. The includer implements ConfigIncluderFile, ConfigIncluderURL
and ConfigIncluderClasspath as well as ConfigIncluder: the parser falls
back to its own handling, which does read the resource, for any of the
typed forms the configured includer does not implement.

Every serializer writes config with ConfigRenderOptions.concise, which
renders JSON and cannot produce an include, so a well-behaved sender is
unaffected.

Result:
Deserializing a message no longer reads local files or issues outbound
requests on behalf of the sender.

Report URL: https://github.com/apache/pekko/actions/runs/33532030938

With regards,
GitHub Actions via GitBox


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to