Conversation
java.net.URL accepts strings that java.net.URI rejects (a space, |, {}, [] in
the path, a stray % or a second #). HttpUrlConnectionDecorator and
UrlConnectionDecorator called URL.toURI(), so every such request threw and
reported a URISyntaxException and lost its http.url, peer and path-based
resource tags.
Add URIUtils.toURI(URL), which percent-encodes only the offending characters
before parsing. Well-formed URLs go through unchanged and without extra
allocation.
Co-Authored-By: Claude Sonnet 5.5 <[email protected]>
This comment has been minimized.
This comment has been minimized.
Contributor
🟢 Java Benchmark SLOs — All performance SLOs passed
PR vs. master results
Commit: Load and DaCapo benchmarks can be triggered manually in the GitLab pipeline. Results will appear in the Benchmarking Platform UI after completion. |
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What Does This Do
Draft / jumping-off point, expect to iterate.
Stops
HttpURLConnectionrequests with common bad-input URLs from throwing and reporting aURISyntaxExceptionon every request.java.net.URLaccepts strings thatjava.net.URIrejects.HttpUrlConnectionDecorator.urlandUrlConnectionDecorator.onURLcalledURL.toURI(), so each such request threw, was caught inHttpClientDecorator.onRequest("Error tagging url"), and ended up with nohttp.url, no peer host/port, and no path-based resource name.URIUtils.toURI(URL), which percent-encodes only whatjava.net.URIrejects before parsing: a space or control character, any of" < > \ ^{ | },[or]in the **path** (they stay legal in the query, fragment and an IPv6 host), a%not followed by two hex digits, and a second#`. Non-ASCII letters are kept; non-ASCII spaces/controls are encoded as UTF-8.url.toURI()would, and return the sameStringwith no extra allocation.URIrejects still throwsURISyntaxException, so existing catch blocks behave as before.HttpUrlConnectionDecorator.urlandUrlConnectionDecorator.onURLnow use it.URIUtilsToURITest(JUnit 5, 17 cases): repaired inputs, unchanged well-formed inputs (compared withurl.toURI()), non-ASCII handling, and a case that must still throw.Motivation
Three Error Tracking issues are this same failure through different entry points:
7eb5eb3c(HttpURLConnection.getInputStream),80a09d2a(HttpURLConnection.connect, currently IGNORED with no recorded reason) and7d87bb46(commons-httpclient, not touched here). Together they are about 200k events a day (all tracer versions; reports aggregate repeats, so the real throw count is higher), and80a09d2ais still ~28% on 1.65.1 / 1.66.0, so upgrading does not make it go away. A latch is the wrong tool because the failure is per URL, so the fix makes the failing case cheap instead of skipping it. Related: APMLP-1881 (guardedsafeParse) and APMLP-1884 (input-rate breaker and per-site counters).Additional Notes
URISyntaxExceptionplus the lost tags; that is reasoned, not measured. A JMH comparing the three paths (well-formed, repaired, throwing) would be a good addition before this leaves draft.http.urland the SSRF check see the percent-encoded form, andURI.getPath()decodes back to the original characters.pathStart/ path-end scan runs on every call and is only needed when the string has a[or]; computing it lazily would make the clean path a single pass (techdebtnoted this;perf-reviewdid not consider it worth flagging).toURI()callers were not touched:OkHttpClientDecorator(okhttp-2.2,request.url().toURI()), and commons-httpclient (new URI(httpMethod.getURI().toString()), a different source type).URIDataAdapter(already used by ~20 server decorators) so that nothing goes through the strictjava.net.URI.java.net.URLalready rejects malformed authorities at construction, so URI failures after the repair should be rare; the "still throws" test uses the multi-argumentURLconstructor, which does not validate the host.internal-apiandagent-bootstrap. CI has not run.Contributor Checklist
type:and (comp:orinst:) labels in addition to any other useful labelsclose,fix, or any linking keywords when referencing an issueUse
solvesinstead, and assign the PR milestone to the issueJira ticket: N/A
🤖 Generated with Claude Code