Skip to content

[P0] arch-guard: ban mutable EventMeshFrame and unbounded attribute maps #5357

Description

@qqeasonchen

Tracking sub-issue of #5354. Part of the production-HA acceptance plan (Phase 0, P0).

What this rule does

  • Ban setter-style methods on EventMeshFrame (no public setAttribute, setPayload, setHeader).
  • Ban exposure of mutable LinkedHashMap from getAttributes() / getHeaders().
  • Ban EventMeshFrame with more than 64 attributes (the limit to be defined in [P0] harden EventMeshFrame: FrameLimits, immutability, fuzz/boundary tests #5361).
  • Ban EventMeshFrame.encode(...) being called from any class other than the codec + the wire package.

Why P0

EventMeshFrame is the single internal data structure (issue #5299 made it the only wire format). If a frame can be mutated after publish, two concurrent dispatchers can race on the same instance. The current EventMeshFrame exposes Map<String, byte[]> getters that return the internal map directly, which the dispatcher can mutate. #5352 calls this out as a hardening target.

Acceptance criteria

  • ruleEventMeshFrameImmutable and ruleEventMeshFrameMaxAttributes exist in ArchitectureRules.java.
  • Matching *_check tests in ArchitectureRulesTest.java exercise:
  • ./gradlew :eventmesh-architecture-guard:test is green.

Verification

./gradlew :eventmesh-architecture-guard:test --tests "*ArchitectureRulesTest*"

Depends on / blocks

References

  • eventmesh-common/src/main/java/org/apache/eventmesh/common/wire/EventMeshFrame.java
  • eventmesh-common/src/main/java/org/apache/eventmesh/common/wire/EventMeshFrameCodec.java
  • eventmesh-architecture-guard/.../ArchitectureRules.java

Part of the production-HA topology in #5354. See also #5352 and #5353.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions