ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

ci: resilient protoc install to fix flaky release-CDN 504s - #557

Merged
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install
Jun 8, 2026
Merged

ci: resilient protoc install to fix flaky release-CDN 504s#557
moonming merged 1 commit into
mainfrom
ci/protoc-resilient-install

Conversation

@moonming

@moonmingmoonming commented Jun 8, 2026

Copy link
Copy Markdown
Member

Problem

arduino/setup-protoc@v3.0.0 flakes intermittently with

Error: Failed to download version v23.4: Unexpected HTTP response: 504

on protoc-23.4-linux-x86_64.zip from the GitHub release CDN (objects.githubusercontent.com). It hits whichever of the four protoc-needing jobs (lint, schema drift, rust unit + coverage, build aisix (instrumented)) loses the lottery, failing unrelated PRs. When build aisix (instrumented) is the loser, the dependent e2e + coverage >= 90% jobs are skipped, so a green-code PR shows red CI (this blocked #550 across three reruns).

repo-token is already set on all four steps — but it only authenticates the GitHub API release lookup, not the asset download, so it does not prevent the 504.

Fix

A local composite action .github/actions/setup-protoc that downloads the same pinned protoc 23.4 with hard retries (curl --retry 5 --retry-all-errors inside an outer 5× loop, 15 s backoff) and installs it under $HOME (no sudo), exposed to later steps via $GITHUB_PATH. Drop-in replacement at all four call sites (−12/+4 in ci.yml).

  • Keeps protoc 23.4 — no risk of a distro protoc (e.g. the apt package on ubuntu-22.04 lacks proto3 optional) silently changing build behavior.
  • DRY — one action / one version / one retry policy for all four jobs (previously four copies of the action block).
  • No sudo — installs under $HOME/.local, pins PROTOC for prost/tonic build scripts.

Validation

This PR modifies the workflow, so its own CI runs every job through the new install path — if they go green (incl. build aisix (instrumented)e2e), the fix is proven against the real flake.

Why not apt / a retry-action

  • apt protobuf-compiler is the simplest "never touch the CDN" fix but changes the protoc version (version-dependent build risk) — rejected to stay zero-risk.
  • A third-party retry-wrapper action adds a supply-chain dependency for what a ~14-line shell step does.

Integrity note: the asset is fetched over HTTPS from GitHub's official release CDN (TLS-authenticated), matching the integrity guarantee of the action it replaces (neither verifies a SHA-256). A pinned checksum can be added later if desired.

@coderabbitai

coderabbitaiBot commented Jun 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@moonming, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 2 minutes and 39 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more in the billing tab.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Free

Run ID: b99b0ef9-4b17-4217-95d5-c4c66a172dd6

📥 Commits

Reviewing files that changed from the base of the PR and between fb1d79c and aefb179.

📒 Files selected for processing (2)
  • .github/actions/setup-protoc/action.yml
  • .github/workflows/ci.yml

Note

🎁 Summarized by CodeRabbit Free

Your organization has reached its limit of developer seats under the Pro Plan. For new users, CodeRabbit will generate a high-level summary and a walkthrough for each pull request. For a comprehensive line-by-line review, please add seats to your subscription by visiting https://app.coderabbit.ai/login.If you believe this is a mistake and have available seats, please assign one to the pull request author through the subscription management page using the link above.

Comment @coderabbitai help to get the list of available commands and usage tips.

arduino/setup-protoc@v3.0.0 downloads protoc-23.4 from the GitHub release CDN
(objects.githubusercontent.com), which intermittently returns HTTP 504. The
asset download is plain CDN traffic — repo-token (already set on all four steps)
only authenticates the GitHub API release lookup, not the download — so the
existing token does not prevent the flake. It hits whichever protoc-needing job
loses the lottery (lint / schema-drift / rust-unit / build-bin), failing
unrelated PRs; when build-bin is the loser, the dependent e2e + coverage jobs
are skipped, so a green-code PR shows red CI.
Replace it with a local composite action .github/actions/setup-protoc that
downloads the SAME pinned protoc 23.4 with hard retries (curl --retry plus an
outer 5x loop, 15s backoff) and installs it under $HOME (no sudo), exposing it
via $GITHUB_PATH and pinning $PROTOC for prost/tonic build scripts. Keeps the
exact version (no build risk from a distro protoc that may lack proto3
'optional') and DRYs the four call sites behind one action.
Refs #550 (whose instrumented build kept losing the 504 lottery).
@moonming
moonmingforce-pushed the ci/protoc-resilient-install branch from b38cdf6 to aefb179CompareJune 8, 2026 07:19
@moonming
moonming merged commit 963068f into mainJun 8, 2026
7 checks passed
@moonming
moonming deleted the ci/protoc-resilient-install branch June 8, 2026 07:40
kilb pushed a commit to kilb/aisix that referenced this pull request Aug 19, 2026
Model rows have carried a source-IP allowlist since api7#557, and a routing
group's members since AISIX-Cloud#1087. MCP servers and A2A agents carried
none. An operator who restricted a model to a source network found the
same restriction unavailable for the MCP server and the A2A agent sitting
beside it in the same environment, with nothing to say why — the field
simply was not there.
`allowed_cidrs` now exists on both resources with the same shape and the
same write-path validation the model field has. The gate itself is ONE
function, `models::model::cidr_allows`, which all three resources call:
its fail-closed handling of an unattributable caller and its
IPv4-mapped-IPv6 canonicalisation were each a real bug fixed once, and a
copy per resource would still have them.
The two endpoints refuse differently, and the code says why at each site:
- `/a2a/<agent>` answers 403. It already discloses that an agent exists by
answering an ACL denial with 403, so hiding only the IP case buys
nothing and would make two refusals for the same agent answer
differently.
- `/mcp/<server>` treats the server as ABSENT — 404 on the scoped route,
and filtered out of the aggregated gateway entirely. Telling a caller a
private MCP server exists but is not theirs hands them the tool
inventory the allowlist exists to withhold, and filtering at gateway
construction is what makes listing and calling agree; a gate applied
only when a tool is invoked would still publish every tool name. Same
existence fold `/v1/videos` applies to an ACL denial.
An empty `allowed_cidrs` is not a deny-all — the field is opt-in, so a row
carrying it without entries serves exactly as a row without it, and
existing servers and agents are unaffected on upgrade.
Half a feature, stated as such: the gateway enforces this today, and an
operator running the open-source gateway can set it through declarative
config. Reaching it from AISIX Cloud needs the control plane to accept the
new field — its validator rejects anything its spec does not list — so
`cp-admin.yaml`, the typed model, the dashboard form and the i18n strings
are the other half. Recorded on the roadmap as Cloud work rather than left
implied by a merged gateway change.
E2E over a real socket, because that is the only place a MATCHING
allowlist can be shown to admit a caller — a oneshot request has no peer
address, so unit tests can pin the refusal and nothing else. It asserts
loopback is admitted, a foreign network is refused on both endpoints with
their respective statuses, and that an unreachable MCP server publishes no
tools. Against the pre-change binary the restricted agent serves with 200.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant

@moonming