fix(talk): fail closed at the SDP HTTP boundary - #32
Conversation
|
🦞👀 Pull request received. I will update this pull request when review starts. ClawSweeper review completeClawSweeper finished reviewing this revision. The review result is being finalized. |
|
Codex review: blocked before merge. Reviewed September 16, 2026, 12:13 AM ET / 04:13 UTC (Revision 5). ClawSweeper reviewWhat this changesTalk now refuses redirects during voice-session negotiation and stops before transmission when HTTP request setup fails, with regression coverage and operator documentation. Merge readiness⛔ Blocked before merge - 1 item remains Still needed on main. The earlier documentation and proof blockers are resolved, and no introduced correctness defect remains. Priority: P2 Review scores
Verification
How this fits togetherThe Talk adapter connects ESP32 voice firmware to Gateway-owned voice sessions. It receives an offer endpoint and broker credential, sends the local session description over HTTP, and passes a successful answer to WebRTC. flowchart TD
A[Gateway session response] --> B[Validate endpoint and credential]
C[Local session description] --> D[Configure HTTP request]
B --> D
D --> E{Setup succeeds?}
E -->|No| F[Fail and clean up]
E -->|Yes| G[Direct HTTP exchange]
G -->|Redirect or error| F
G -->|Valid successful answer| H[Deliver answer to WebRTC]
Before merge
Agent review detailsSecurityNone. Review metrics
Merge-risk optionsMaintainer options:
Technical reviewBest possible solution: Keep credentials confined to the direct offer endpoint and retain the documented proxy migration backed by the supplied direct-exchange recovery proof. Do we have a high-confidence way to reproduce the issue? Yes: current-main source and the SDK redirect contract establish the path, and the supplied native baseline trace demonstrates credential forwarding. This read-only review did not execute the harness. Is this the best way to solve the issue? Yes: the SDK's redirect switch and a pre-transmission error guard repair the existing boundary without a parallel transport implementation; the deliberate compatibility change has documentation and recovery proof. AGENTS.md: not found in the target repository. Codex review notes: model internal, reasoning medium; reviewed against 31b2cf08cabc. LabelsLabel changes:
Label justifications:
EvidenceWhat I checked:
Likely related people:
Rating scale
Overall follows the weaker of proof and patch quality. Workflow
HistoryReview history (4 earlier review cycles)
|
c84b574 to
d4d3002
Compare
|
@clawsweeper re-review |
|
🦞🧹 I asked ClawSweeper to review this item again. Re-review progress:
|
d4d3002 to
609e7cf
Compare
Refuse redirects carrying the broker credential and stop before perform when any request header or body setup fails. Exercise the production signaling path with direct success, redirect and setup-failure regressions, preserving threaded diagnostics and cleanup assertions. Co-authored-by: Sebastien Tardif <sebtardif@ncf.ca>
609e7cf to
8592d4d
Compare
Talk now keeps its single-use broker credential on the direct
offerUrlby disabling automatic HTTP redirects. All non-2xx responses fail the exchange. The same HTTP boundary also ignored failed Content-Type, Authorization, extra-header and POST-body configuration; those failures now stop before transmission, clean up the client and deliver no SDP answer. The first-failure diagnostics are preserved and their documentation now describes the fatal setup errors correctly.This reworks @SebTardif's PR, preserves contributor credit, and includes the related request-setup bug found while checking the send path. The Gateway or reverse proxy must provide the final offer endpoint, including when a same-origin redirect was previously used. No public API, dependency version or release changes.
Real transport proof
The new repeatable native harness builds actual production Talk C with ESP-IDF's HTTP client, TCP transport, FreeRTOS and cJSON, then runs the binary against two loopback HTTP servers. HTTP functions are not replaced. Only the Gateway session response/close and peer answer callback are synthetic. The run used macOS and ESP-IDF 5.5.5; it does not qualify TLS, Wi-Fi, media or physical boards.
# Activate ESP-IDF and configure the component-test app's cJSON dependency first. python3 components/esp-openclaw-talk/tests/run_http_host_tests.pyOn unchanged main source
7b8b32d, all ten 301/302/303/307/308 cases, across both same-origin and cross-port destinations, produced two requests and one credential-bearing redirected request. With the fixed source, every redirect fails with one request, zero redirected requests and zero answers. Direct authenticated POST succeeds both before and after those cases:The runner accepts existing cJSON/WebRTC paths, an external persistent build directory, and a production-source override for repeating baseline failures. Its default build is temporary. It binds only loopback and uses synthetic data/credentials.
Regression and build validation
All 19 routing tests pass with ASan/UBSan, covering direct success, redirect statuses, every setup failure, cleanup, and an earlier offer-header failure followed by a successful later header. All 24 threaded ownership/diagnostics cases pass with real SDK headers under both ASan/UBSan and TSan. Existing diagnostics assertions that expected ignored setup errors now require failure, zero HTTP performs/answers and preserved cleanup/diagnostics.
Independent autoreview is clean through P2 for the final staged candidate. The native HTTP fixture also passed its fresh build and all 12 network exchanges. Optional Clang analysis produces one baseline-matching test-path lifetime warning, reproduced with unchanged main source and the same fixture; sanitizer execution passes, and no suppression was added.
Final head
8592d4dc79ede294d867a9e4b5cd62d2541e6e29passed all five native firmware builds, the registered file-command suite, 19 routing cases, 24 threaded cases and 49 room lifecycle cases. Tab5 used the exact documented SDK base plus verified SDK/SDIO/camera patches, and its compiled-camera verification passed. The earlier #32 candidate passed its full five-target CI matrix; all five final-head CI builds passed at8592d4dc79ede294d867a9e4b5cd62d2541e6e29.