test(api): logbounds — a marker the random request id cannot contain (#1460)

TestBoundRequestID_ControlBytesRejected asserted that "abc" never reaches
the log record, but the server-generated fallback id is a short random base64
run and contained "abc" by chance in CI run 33308823281
(req_id=runnervmgx7h7/qj9LabcvlI-000002), failing an unrelated PR. The marker
is now a long distinctive token, and the test also asserts a request id was
logged at all, as its sibling does.


Claude-Session: https://claude.ai/code/session_01KmiqjgTuov1stBTB6uGkvo

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
J3vb
2026-08-30 16:06:55 +00:00
committed by GitHub
co-authored by Claude Fable 5
parent f92452124d
commit e01061208d
+10 -3
View File
@@ -60,16 +60,23 @@ func TestBoundRequestID_OverLongHeaderNeverReachesLog(t *testing.T) {
}
// TestBoundRequestID_ControlBytesRejected covers the charset half of the bound:
// a short id carrying control bytes is dropped too.
// a short id carrying control bytes is dropped too. The marker is long and
// distinctive on purpose: the server-generated fallback id is a short random
// base64 run, and a three-letter marker ("abc") once matched inside it by
// chance (CI run 33308823281, req_id=…/qj9LabcvlI-000002).
func TestBoundRequestID_ControlBytesRejected(t *testing.T) {
const marker = "ILLFORMEDREQUESTID"
req := httptest.NewRequest(http.MethodGet, "/api/v1/health", nil)
req.Header.Set("X-Request-Id", "abc\x00def\tghi")
req.Header.Set("X-Request-Id", marker+"\x00def\tghi")
out, _ := loggedRequest(t, req)
if strings.Contains(out, "abc") {
if strings.Contains(out, marker) {
t.Errorf("ill-formed X-Request-Id reached the log record: %q", out)
}
if !strings.Contains(out, "req_id=") {
t.Errorf("no request id was logged at all — correlation lost: %q", out)
}
}
// TestBoundRequestID_NormalIDPreserved proves the bound does not break the