Repository navigation
fix(vmafx-mcp): harden HTTP server against Slowloris + bound shutdown - #300
Merged
Merged
Conversation
lusoris
marked this pull request as draft
May 30, 2026 14:42
This was referenced May 30, 2026
lusoris
marked this pull request as ready for review
May 31, 2026 13:26
lusoris
force-pushed
the
fix/vmafx-mcp-http-slowloris-and-shutdown
branch
from
May 31, 2026 13:26
1092421 to
41cf77d
Compare
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Add unit tests for the lowest-coverage Go cmd/ subpackages identified by the master-tip workflow audit (Section F). No behavior change. Coverage deltas (against origin/master tip bbcaa8d): cmd/vmafx-controller 18.6% -> 32.4% (+13.8 pp) cmd/vmafx-controller/nodes 80.7% -> 82.5% (+1.8 pp) cmd/vmafx-server 27.5% -> 47.9% (+20.4 pp) cmd/vmafx-mcp 3.5% -> 24.6% (+21.1 pp) New test files: - cmd/vmafx-controller/main_extra_test.go 405 method-not-allowed on /healthz, /readyz, /v1/score; 400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout; envOr default+override; version(). - cmd/vmafx-controller/nodes/registry_edge_test.go Get(unknown), distinct-IDs-for-same-name contract pin, Heartbeat updates JobsRunning + advances LastHeartbeat (reaper eviction predicate), concurrent Register/Heartbeat under -race, defensive-copy assertion on All(). - cmd/vmafx-server/main_extra_test.go Same shape as the controller HTTP server tests; pins the PR #300 bounded-timeout shutdown invariant. - cmd/vmafx-mcp/impl_test.go All arg helpers (strArg, intArg, floatArg, boolArg, hasArg); every pure helper (classifySourceResolution, modelResolutionClass, resolutionMismatchWarning, inferBackendFromPayload, inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames, floatFromAny, roundF, truncate); representative handler error paths (handleProbeBackend missing/unknown backend, handleDescribeModel missing name, handleVmafScore invalid path / zero dimensions, handleCompareModels empty list). Pins the errorResult().IsError == true invariant from project memory (MCP isError must be True so clients branch correctly). Drive-by fix: .gitignore anchored the Go binary-ignore rules with a leading slash so they only match the repo-root binaries, not any path component sharing the name. Without this, untracked files like cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`. Verification: go test -race -cover ./cmd/vmafx-controller/... \ ./cmd/vmafx-server/... \ ./cmd/vmafx-mcp/... go vet ./... All green; no behavior change. The pre-existing cmd/vmafx-operator/internal/controller failure (kubebuilder envtest needs etcd binaries on PATH) is unrelated to this change and reproduces on a clean origin/master checkout. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Add unit tests for the lowest-coverage Go cmd/ subpackages identified by the master-tip workflow audit (Section F). No behavior change. Coverage deltas (against origin/master tip bbcaa8d): cmd/vmafx-controller 18.6% -> 32.4% (+13.8 pp) cmd/vmafx-controller/nodes 80.7% -> 82.5% (+1.8 pp) cmd/vmafx-server 27.5% -> 47.9% (+20.4 pp) cmd/vmafx-mcp 3.5% -> 24.6% (+21.1 pp) New test files: - cmd/vmafx-controller/main_extra_test.go 405 method-not-allowed on /healthz, /readyz, /v1/score; 400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout; envOr default+override; version(). - cmd/vmafx-controller/nodes/registry_edge_test.go Get(unknown), distinct-IDs-for-same-name contract pin, Heartbeat updates JobsRunning + advances LastHeartbeat (reaper eviction predicate), concurrent Register/Heartbeat under -race, defensive-copy assertion on All(). - cmd/vmafx-server/main_extra_test.go Same shape as the controller HTTP server tests; pins the PR #300 bounded-timeout shutdown invariant. - cmd/vmafx-mcp/impl_test.go All arg helpers (strArg, intArg, floatArg, boolArg, hasArg); every pure helper (classifySourceResolution, modelResolutionClass, resolutionMismatchWarning, inferBackendFromPayload, inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames, floatFromAny, roundF, truncate); representative handler error paths (handleProbeBackend missing/unknown backend, handleDescribeModel missing name, handleVmafScore invalid path / zero dimensions, handleCompareModels empty list). Pins the errorResult().IsError == true invariant from project memory (MCP isError must be True so clients branch correctly). Drive-by fix: .gitignore anchored the Go binary-ignore rules with a leading slash so they only match the repo-root binaries, not any path component sharing the name. Without this, untracked files like cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`. Verification: go test -race -cover ./cmd/vmafx-controller/... \ ./cmd/vmafx-server/... \ ./cmd/vmafx-mcp/... go vet ./... All green; no behavior change. The pre-existing cmd/vmafx-operator/internal/controller failure (kubebuilder envtest needs etcd binaries on PATH) is unrelated to this change and reproduces on a clean origin/master checkout. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
Add unit tests for the lowest-coverage Go cmd/ subpackages identified by the master-tip workflow audit (Section F). No behavior change. Coverage deltas (against origin/master tip bbcaa8d): cmd/vmafx-controller 18.6% -> 32.4% (+13.8 pp) cmd/vmafx-controller/nodes 80.7% -> 82.5% (+1.8 pp) cmd/vmafx-server 27.5% -> 47.9% (+20.4 pp) cmd/vmafx-mcp 3.5% -> 24.6% (+21.1 pp) New test files: - cmd/vmafx-controller/main_extra_test.go 405 method-not-allowed on /healthz, /readyz, /v1/score; 400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout; envOr default+override; version(). - cmd/vmafx-controller/nodes/registry_edge_test.go Get(unknown), distinct-IDs-for-same-name contract pin, Heartbeat updates JobsRunning + advances LastHeartbeat (reaper eviction predicate), concurrent Register/Heartbeat under -race, defensive-copy assertion on All(). - cmd/vmafx-server/main_extra_test.go Same shape as the controller HTTP server tests; pins the PR #300 bounded-timeout shutdown invariant. - cmd/vmafx-mcp/impl_test.go All arg helpers (strArg, intArg, floatArg, boolArg, hasArg); every pure helper (classifySourceResolution, modelResolutionClass, resolutionMismatchWarning, inferBackendFromPayload, inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames, floatFromAny, roundF, truncate); representative handler error paths (handleProbeBackend missing/unknown backend, handleDescribeModel missing name, handleVmafScore invalid path / zero dimensions, handleCompareModels empty list). Pins the errorResult().IsError == true invariant from project memory (MCP isError must be True so clients branch correctly). Drive-by fix: .gitignore anchored the Go binary-ignore rules with a leading slash so they only match the repo-root binaries, not any path component sharing the name. Without this, untracked files like cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`. Verification: go test -race -cover ./cmd/vmafx-controller/... \ ./cmd/vmafx-server/... \ ./cmd/vmafx-mcp/... go vet ./... All green; no behavior change. The pre-existing cmd/vmafx-operator/internal/controller failure (kubebuilder envtest needs etcd binaries on PATH) is unrelated to this change and reproduces on a clean origin/master checkout. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
lusoris
added a commit
that referenced
this pull request
Jun 3, 2026
…overage + #336 state.md row sweep + #383 README badges + #337 ADR-0865 ANSNR) (#529) * docs(libvmaf): doxygen comments on 15 undocumented public C-API entry points Round-2 follow-on to PR #302 (which closed five targeted gap-findings in libvmaf.h / picture.h / dnn.h). This pass covers the public surfaces that PR #302 left untouched, focusing on the headers the ffmpeg patch stack, the upcoming Go/Rust bindings, and the embedded MCP server consume. Entry points documented: - feature.h (file was 100 % undocumented): - VmafFeatureDictionary (struct doc + ownership-transfer rules) - vmaf_feature_dictionary_set - vmaf_feature_dictionary_free - model.h: - VmafModelFlags (enum + per-flag semantics) - VmafModelConfig (struct + per-field doc) - vmaf_model_load - vmaf_model_load_from_path - vmaf_model_feature_overload (incl. opts_dict ownership transfer) - vmaf_model_destroy (incl. do-not-destroy-after-collection-handoff) - VmafModelCollection (struct doc) - VmafModelCollectionScoreType (enum doc) - VmafModelCollectionScore (struct + per-field doc) - vmaf_model_collection_load - vmaf_model_collection_load_from_path - vmaf_model_collection_feature_overload - vmaf_model_collection_destroy - dnn.h: - vmaf_dnn_session_close (pair-with-open contract) Each block documents the negative-errno return convention, NULL-safety, ownership-transfer semantics, and the destroy-pairing required to avoid double-free of collection-owned sub-models. No semantic / no ABI change. Cleanup pass (CLAUDE.md §12 r12 — touched-file lint-clean rule): the three Netflix-copyright include guards (__VMAF_FEATURE_H__ / __VMAF_MODEL_H__ / __VMAF_DNN_H__) trip clang-tidy's bugprone-reserved-identifier check. Renaming them would diverge from Netflix/vmaf master and break port-only upstream sync (CLAUDE.md §10), so each #ifndef / #define gets an inline NOLINT citing the upstream-mirror invariant — the exact pattern ADR-0278 endorses for load-bearing upstream-parity identifiers. Build + lint: - meson setup build-cpu-doc core -Denable_cuda=false -Denable_sycl=false - ninja -C build-cpu-doc (35 targets touched by header change; clean) - clang-tidy -p build-cpu-doc on all 3 touched headers: 0 fork-local warnings (the 3 reserved-identifier warnings present on master are now NOLINT-cited; remaining warnings are in system headers and suppressed). - pre-commit run --files <all 5 touched files>: green. ADR-0108 deliverables: - Research digest: no digest needed — trivial doc-only addition over Netflix-stable signatures already covered by the existing reference manual. - Decision matrix: no alternatives needed — only-one-way fix; the ownership-transfer text matches the implementation in core/src/model.c and core/src/dict.c verbatim. - AGENTS.md invariant note: no rebase-sensitive invariants — the doc text sits above unchanged upstream signatures; future merges from Netflix produce tractable 3-way merges. The NOLINT cites name the invariant they preserve (upstream-mirror include guards). - Reproducer / smoke test: see PR body. - Changelog fragment: changelog.d/added/libvmaf-public-header-doc-comments-round2.md. - Rebase notes: docs/rebase-notes.md updated with a dedicated section. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * test(go): expand cmd/vmafx-{controller,server,mcp} coverage Add unit tests for the lowest-coverage Go cmd/ subpackages identified by the master-tip workflow audit (Section F). No behavior change. Coverage deltas (against origin/master tip bbcaa8d): cmd/vmafx-controller 18.6% -> 32.4% (+13.8 pp) cmd/vmafx-controller/nodes 80.7% -> 82.5% (+1.8 pp) cmd/vmafx-server 27.5% -> 47.9% (+20.4 pp) cmd/vmafx-mcp 3.5% -> 24.6% (+21.1 pp) New test files: - cmd/vmafx-controller/main_extra_test.go 405 method-not-allowed on /healthz, /readyz, /v1/score; 400 invalid-JSON body; 500 scorer-error mapping via a stub vmaf binary; runHTTP graceful shutdown bounded by GracefulShutdownTimeout; envOr default+override; version(). - cmd/vmafx-controller/nodes/registry_edge_test.go Get(unknown), distinct-IDs-for-same-name contract pin, Heartbeat updates JobsRunning + advances LastHeartbeat (reaper eviction predicate), concurrent Register/Heartbeat under -race, defensive-copy assertion on All(). - cmd/vmafx-server/main_extra_test.go Same shape as the controller HTTP server tests; pins the PR #300 bounded-timeout shutdown invariant. - cmd/vmafx-mcp/impl_test.go All arg helpers (strArg, intArg, floatArg, boolArg, hasArg); every pure helper (classifySourceResolution, modelResolutionClass, resolutionMismatchWarning, inferBackendFromPayload, inferBackendFromSym, stripModelExt, toFFmpegPixfmt, pickWorstFrames, floatFromAny, roundF, truncate); representative handler error paths (handleProbeBackend missing/unknown backend, handleDescribeModel missing name, handleVmafScore invalid path / zero dimensions, handleCompareModels empty list). Pins the errorResult().IsError == true invariant from project memory (MCP isError must be True so clients branch correctly). Drive-by fix: .gitignore anchored the Go binary-ignore rules with a leading slash so they only match the repo-root binaries, not any path component sharing the name. Without this, untracked files like cmd/vmafx-server/main_extra_test.go were silently ignored by `git add`. Verification: go test -race -cover ./cmd/vmafx-controller/... \ ./cmd/vmafx-server/... \ ./cmd/vmafx-mcp/... go vet ./... All green; no behavior change. The pre-existing cmd/vmafx-operator/internal/controller failure (kubebuilder envtest needs etcd binaries on PATH) is unrelated to this change and reproduces on a clean origin/master checkout. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * docs(state): reconcile 2 Open rows that cited CLOSED PRs (#214, #215) Two Open rows in docs/state.md cited PRs that were CLOSED-not-merged and flagged as follow-up by the PR #291 closing agent. Verified against master tip bbcaa8d and master state of the underlying issues: 1. T-CUDA-FILTER1D-RES-DISPATCH-CONFLICT-2026-05-29 — migrated from Open to Recently closed (superseded). The conflict markers only existed on the unmerged scaffold branch tip 35a1fb6. PR #91 (merged 2026-05-29T09:37:48Z) landed ADR-0753 resolution-aware dispatch via the adm_cm_device() consumer without extending dispatch into filter1d_8(), so master never carried the build-failing scaffold variant. PR #214 (the planned conflict-marker cleanup) was CLOSED-not-merged 2026-05-30 when its base scaffold branch was abandoned. core/src/feature/cuda/ integer_vif_cuda.c::filter1d_8() on master uses the clean unconditional cuLaunchKernel paths. 2. T-CPP23-READ-JSON-MODEL-PENDING-2026-05-29 — kept Open but the dead PR #215 citation removed. The C++23 Wave 8 conversion of core/src/read_json_model.c is still pending on master (still a .c source per core/src/meson.build:1578); PR #215 was CLOSED-not-merged 2026-05-30. Owner field rewritten to "Owner-driven; pending fresh PR per ADR-0846 Wave 8". Scope-coordinated with DRAFT PR #291 (docs/state-md-drift-sync — already migrates the 3 Vulkan rows + T-LEGACY-RUNNER-ANSNR-BROKEN + T-LEGACY-RUNNER-STUB-MISSING). Row 203 (T-LEGACY-RUNNER-STUB-MISSING-2026-05-29) cites closed PRs #213 and #181 as OPEN but is left untouched here since PR #291 already rewrites it. Net Open count -1; total T-row count unchanged (153). No code changes — documentation cleanup only. Deliverables (ADR-0108): - no digest needed: state.md hygiene - no alternatives: only-one-way reconciliation - no rebase-sensitive invariants - Reproducer: `gh pr view 214 -R VMAFx/vmafx --json state,mergedAt` returns `{"state":"CLOSED","mergedAt":null}`; `grep -nE '^(<{7}|={7}|>{7})( |$)' core/src/feature/cuda/integer_vif_cuda.c` on master returns empty; `ls core/src/read_json_model.*` returns only `.c` and `.h`. - Changelog: changelog.d/changed/state-md-closed-pr-row-sweep.md - no rebase impact: docs only Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * chore(meta): README badge audit + Cargo / pyproject repo-metadata sweep Audit + backfill the fork's repo-metadata surface so cargo / pip / GitHub all advertise the canonical VMAFx/vmafx URLs: - README.md: add Rust CI + Go CI workflow badges (both workflows ship on master but were not surfaced). All five pre-existing workflow badges already point at VMAFx/vmafx and reference real, active, master-green workflows; verified via the Actions API. License, Conventional Commits, OpenSSF Scorecard, ko-fi badges already present. - Cargo.toml: add [workspace.package] with repository / homepage / documentation / license / authors. Both workspace members (bindings/rust/vmafx-sys, core/src/feature/rust/tad) switched to workspace-inherited metadata so URL drift is impossible across the Rust workspace. cargo metadata confirms both crates now expose the VMAFx/vmafx URLs. - pyproject.toml (root, ai/, tools/vmaf-tune, tools/vmaf-roi-score, tools/ensemble-training-kit, dev-llm/, mcp-server/vmaf-mcp/): add [project.urls] with Homepage / Repository / Documentation / Issues / Changelog. All seven fork-authored projects now ship the same URL block; the package indexes (PyPI / internal) get a consistent repository link. - deploy/helm/vmafx/Chart.yaml: already correct (home + sources already point at VMAFx/vmafx). No change needed. - changelog.d/fixed/ + docs/rebase-notes.md: deliverables. Coordination with PR #331 (rebrand sweep): #331 only touches the line-1 copyright header of two of the seven pyproject files; this PR adds a new [project.urls] block below — no merge conflict. Deep-dive deliverables (ADR-0108): - Research digest: no digest needed: trivial repo-metadata sweep. - Decision matrix: no alternatives: only-one-way fix (URLs must match the rebrand target). - AGENTS.md invariant: no rebase-sensitive invariants — fork-only metadata files, none mirror upstream Netflix. - Reproducer: `cargo metadata --no-deps --format-version 1 | jq` + `python3 -c "import tomllib; tomllib.loads(open('pyproject.toml','rb').read().decode())"`. - CHANGELOG fragment: changelog.d/fixed/readme-badges-metadata-audit.md. - Rebase note: added to docs/rebase-notes.md (impact: none, fork-only). * docs(adr): author ADR-0865 for ANSNR sunset (closes PR #38 ADR-0108 gap) PR #38 (merged 2026-05-28) removed `float_ansnr` from the C backend but cited `Parent ADR-0709` in its body — ADR-0709 is the Phase 4b distributed-platform umbrella and contains zero ANSNR content. PR #295 + PR #324 inherited the bad cite. No dedicated ANSNR-sunset ADR existed in tree. This change: - Authors `docs/adr/0865-ansnr-sunset-pre-vmaf-metric-drop.md` as the missing parent ADR, back-dated to 2026-05-28 (PR #38 merge date) so the dependency chain (ADR-0865 -> PR #38 -> ADR-0749 Python sunset) is consistent. - Documents the historical mis-cite in the new ADR's `## Notes` section so future readers landing on PR #38 can recover the trail. PR bodies on the remote are immutable merge-history and cannot be rewritten. - Adds the index fragment + `_order.txt` row; regenerates `docs/adr/README.md` via `scripts/docs/concat-adr-index.sh`. - Adds `docs/state.md` row (Updated note + Recently-closed entry). - Adds `docs/rebase-notes.md` entry documenting the rebase invariant (upstream still ships `ansnr` extractors; fork must keep deleting). - Adds `changelog.d/changed/ansnr-sunset-adr-authoring.md` fragment. In-tree audit confirmed zero `ADR-0709` references mis-cite ANSNR — all remaining tree-side `ADR-0709` cites correctly point at Phase 4b distributed-platform content. No tree-side citation fix-up required. Docs-only PR. No code changes. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com> * chore(bundle): add changelog fragment for doc-sweep bundle batch-1 Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 4.7 <noreply@anthropic.com> Co-authored-by: Lusoris <lusoris@pm.me>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
cmd/vmafx-mcp/main.go(~L63) constructed its&http.Server{...}literal with only
Addr+Handler, leavingReadHeaderTimeout,ReadTimeout,WriteTimeout, andIdleTimeoutat their default0(no limit). That is a textbook CWE-400 Slowloris vector:a misbehaving client can dribble header bytes indefinitely, hold
connections open, and exhaust the server's goroutine and FD budget.
srv.Shutdown(context.Background())with no deadline, so a stalled in-flight request could hang the
shutdown forever and prevent the process from exiting.
cmd/vmafx-server/http_server.go(runHTTP, ~L171–190): fourtimeouts on the
http.Serverliteral +context.WithTimeout(..., observability.GracefulShutdownTimeout)(30s) wrapping theShutdowncall.Diff (essence)
ADR-0108 deliverables checklist
hardening against a textbook CWE-400 (Slowloris) vector; the
authoritative pattern is already in tree at
cmd/vmafx-server/http_server.go.four Go
net/httptimeouts + bounded shutdown are the standardhardening, and the concrete values are reused verbatim from the
vmafx-server hardening (already justified there).
cmd/vmafx-mcp/main.gois a fork-added Go file (ADR-0703 family);it has no upstream Netflix/vmaf counterpart, so no rebase conflict
is possible.
cd <repo> && go vet ./cmd/vmafx-mcp/... && go build ./cmd/vmafx-mcp/both succeed. Manual Slowloris probebefore/after:
slowhttptest -c 200 -H -u http://127.0.0.1:3000—pre-fix the server holds the connections open until OS-level FD
exhaustion; post-fix every slow header drip is dropped after the
10s
ReadHeaderTimeout.changelog.d/fixed/vmafx-mcp-http-server-hardening.md(per ADR-0221;rolled into
CHANGELOG.mdbyscripts/release/concat-changelog-fragments.sh).cmd/vmafx-mcp/main.goisfork-added (Go), has no upstream counterpart in Netflix/vmaf, and
cannot conflict on
/sync-upstreamruns.Test plan
go vet ./cmd/vmafx-mcp/...— clean.go build ./cmd/vmafx-mcp/— succeeds.pre-commit run --files cmd/vmafx-mcp/main.go changelog.d/fixed/vmafx-mcp-http-server-hardening.md— all hookspass.
slowhttptestSlowloris probe against therunning binary — refused after 10s instead of indefinitely held.
Out of scope
Handlertimeouts inside the MCP streamable transport(those are owned by the SDK).
ingress / sidecar.
back-fills the pattern to vmafx-mcp).
Refs: ADR-0703 (vmafx-server Go service scaffolding pattern reused
here), ADR-0108 (deliverables checklist).