Sitelet https://github.com/apache/logging-log4net/pull/328
Skip to content

report who accepted the connection in ListenAddressBindsOnlyThatAddress - #328

Merged
FreeAndNil merged 2 commits into
masterfrom
Feature/328-telnet-listen-address-diagnostics
Sep 28, 2026
Merged

FreeAndNil merged 2 commits into
masterfrom
Feature/328-telnet-listen-address-diagnostics

Conversation

@FreeAndNil

@FreeAndNil FreeAndNil commented Sep 25, 2026 •

Copy link
Copy Markdown
Contributor

ListenAddressBindsOnlyThatAddress asserted Throws.TypeOf<SocketException>(), so a failure said
only that no exception was thrown. Not enough on a CI agent to tell whether the appender bound
wrongly or something else on the machine listens on that port.

The assertion now carries a message, built only when it fails:

  • the endpoints of the socket that got through,
  • host name resolution and every interface with its unicast addresses,
  • every listener on that port,
  • what the peer sends first, which names it, since the appender greets every client.

Test-only, one file, no changelog entry.

@FreeAndNil FreeAndNil added this to the 3.5.0 milestone Sep 25, 2026
FreeAndNil added a commit that referenced this pull request Sep 27, 2026
build-release.ps1 built the binaries from the working tree but archived the
local master ref, so the signed source zip need not match the signed binaries.

* Refuse a dirty tree, archive HEAD, and ship a signed .manifest recording the
  commit and the artifact set. No origin/master check: that needs the network
  and forbids cutting a release from a tag or a release branch.
* Both verifiers check the commit against the zip archive comment and the
  listed set against the files present. The hash and signature loops only see
  the files that are there, so an artifact deleted with its .sha512 and .asc
  passed before.
* Everything the release writes gets LF, asserted in the tests. Set-Content
  writes CRLF on Windows, where a trailing CR breaks sha512sum on macOS and
  makes every manifest name compare unequal. Includes the .sha512 fix from
  #328; #328 gets rebased onto this.
* sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An
  empty directory iterated the glob patterns and still exited 0.

audit da18b6f-f025
@FreeAndNil
FreeAndNil force-pushed the Feature/328-telnet-listen-address-diagnostics branch 2 times, most recently from adfae84 to 44bc08c Compare September 27, 2026 20:18
FreeAndNil added a commit that referenced this pull request Sep 27, 2026
build-release.ps1 built the binaries from the working tree but archived the
local master ref, so the signed source zip need not match the signed binaries.

* Refuse a dirty tree, archive HEAD, and ship a signed .manifest recording the
  commit and the artifact set. No origin/master check: that needs the network
  and forbids cutting a release from a tag or a release branch.
* Both verifiers check the commit against the zip archive comment and the
  listed set against the files present. The hash and signature loops only see
  the files that are there, so an artifact deleted with its .sha512 and .asc
  passed before.
* Everything the release writes gets LF, asserted in the tests. Set-Content
  writes CRLF on Windows, where a trailing CR breaks sha512sum on macOS and
  makes every manifest name compare unequal. Includes the .sha512 fix from
  #328; #328 gets rebased onto this.
* sign-log4net-libraries.sh gains set -euo pipefail and shopt -s nullglob. An
  empty directory iterated the glob patterns and still exited 0.

audit da18b6f-f025
@FreeAndNil
FreeAndNil force-pushed the Feature/328-telnet-listen-address-diagnostics branch from 44bc08c to 83147db Compare September 27, 2026 20:22
@FreeAndNil
FreeAndNil force-pushed the Feature/328-telnet-listen-address-diagnostics branch from 83147db to e82b676 Compare September 28, 2026 06:43
FreeAndNil added a commit that referenced this pull request Sep 28, 2026
- A filtering proxy (ESET on Linux) accepts the connection and closes
  it, so a successful connect does not mean the appender is reachable
- The test now fails only on the greeting or the too-many-connections
  reply, which only a wrongly bound appender sends
@FreeAndNil
FreeAndNil marked this pull request as ready for review September 28, 2026 07:53
- A filtering proxy (ESET on Linux) accepts the connection and closes
  it, so a successful connect does not mean the appender is reachable
- The test now fails only on the greeting or the too-many-connections
  reply, which only a wrongly bound appender sends
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants