You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Ban EventMeshFrame.encode(...) being called from any class other than the codec + the wire package.
Why P0
EventMeshFrame is the single internal data structure (issue #5299 made it the only wire format). If a frame can be mutated after publish, two concurrent dispatchers can race on the same instance. The current EventMeshFrame exposes Map<String, byte[]> getters that return the internal map directly, which the dispatcher can mutate. #5352 calls this out as a hardening target.
Acceptance criteria
ruleEventMeshFrameImmutable and ruleEventMeshFrameMaxAttributes exist in ArchitectureRules.java.
Matching *_check tests in ArchitectureRulesTest.java exercise:
Tracking sub-issue of #5354. Part of the production-HA acceptance plan (Phase 0, P0).
What this rule does
EventMeshFrame(no publicsetAttribute,setPayload,setHeader).LinkedHashMapfromgetAttributes()/getHeaders().EventMeshFramewith more than 64 attributes (the limit to be defined in [P0] harden EventMeshFrame: FrameLimits, immutability, fuzz/boundary tests #5361).EventMeshFrame.encode(...)being called from any class other than the codec + the wire package.Why P0
EventMeshFrameis the single internal data structure (issue #5299 made it the only wire format). If a frame can be mutated after publish, two concurrent dispatchers can race on the same instance. The currentEventMeshFrameexposesMap<String, byte[]>getters that return the internal map directly, which the dispatcher can mutate. #5352 calls this out as a hardening target.Acceptance criteria
ruleEventMeshFrameImmutableandruleEventMeshFrameMaxAttributesexist inArchitectureRules.java.*_checktests inArchitectureRulesTest.javaexercise:EventMeshFramehas no public setters,./gradlew :eventmesh-architecture-guard:testis green.Verification
./gradlew :eventmesh-architecture-guard:test --tests "*ArchitectureRulesTest*"Depends on / blocks
References
eventmesh-common/src/main/java/org/apache/eventmesh/common/wire/EventMeshFrame.javaeventmesh-common/src/main/java/org/apache/eventmesh/common/wire/EventMeshFrameCodec.javaeventmesh-architecture-guard/.../ArchitectureRules.javaPart of the production-HA topology in #5354. See also #5352 and #5353.