Skip to content

fix(config): refuse a negative pool_size in redis.url - #2079

Open
blurbery wants to merge 1 commit into
Silo-Server:mainfrom
blurbery:fix/redis-negative-pool-size
Open

blurbery wants to merge 1 commit into
Silo-Server:mainfrom
blurbery:fix/redis-negative-pool-size

Conversation

@blurbery

@blurbery blurbery commented Oct 8, 2026 •

Copy link
Copy Markdown
Contributor

Problem

Closes #1862
Related issue: #1861
Validation tasks: none

A redis.url with a negative pool_size (for example redis://redis:6379?pool_size=-1) passes validation, and go-redis panics when a client is built from it. The admin connection check answers 500 with a handler panic, the save is accepted, and the next start panics before anyone can fix the value in the admin UI. #1862 has the full reproduction. This change refuses a negative pool_size when the URL is parsed, so the save answers 422 naming the option and the connection check reports a failed check, as they already do for pool_size=many.

go-redis replaces a pool_size of 0 with its default, but uses any other value as the size of its pool's semaphore channel, so a negative one panics in NewClient with makechan: size out of range. Since Sentinel URLs became supported (#1859), the same happens for them: the master client gets the same pool size.

Approach

  • ParseRedisURL returns redis: pool_size must be 0 or more; leave it out for the default for a negative pool_size, for both single-server and Sentinel URLs. NormalizeRedisURL, the connection check and startup all go through it, so the save refuses it and nothing builds a client from it.
  • Other negative pool options (min_idle_conns, max_idle_conns, max_active_conns, max_concurrent_dials) are left alone. go-redis ignores or clamps them, and refusing them would stop a server that starts today, because startup exits when its saved URL can't be used (A saved redis.url that Silo cannot connect with stops the server at the next start #1861).

A server that already has pool_size=-1 saved still can't start, but with a clear error instead of a panic. Recovering from a saved URL that doesn't work is #1861.

Validation

  • Tests in internal/config refuse pool_size=-1 in single-server and Sentinel URLs, check the error names the option, build a go-redis client from every pool size ParseRedisURL accepts (0 and 20 still work), and check NormalizeRedisURL refuses it. On ca186fe they fail: both URLs parse, building a client panics with makechan: size out of range, and the save accepts it.
  • go test ./internal/config/ passes. go vet and make lint-changed: clean.
  • CI on 9165365: every job passed (run).
  • Not run on a server with this change.

Benchmarks

Not applicable. This only adds a check when the URL is parsed.

Evidence

Evidence: https://evidence.siloserver.org/r/silo-server/pr-2079/

Before: the reproduction in #1862 and the failing tests. After: the save refuses the URL with an error naming pool_size.

Risks

None identified. A negative pool_size could never build a client, so no working setup is refused.

Checklist

  • I read and can explain the complete diff.
  • This pull request addresses one concern.
  • The Evidence section shows every change a user can see, or says there is none.

AI Disclosure

  • Harness: Claude Code (desktop app)
  • Tool(s): Claude Code, go, gh
  • Model(s): claude-opus-5-5
  • Involvement: AI-assisted
  • Adversarial review: n/a, small validation change

AI-assisted with Claude Opus. I directed the task and designed the work.

go-redis replaces only a pool_size of 0 with its default and panics
building a client from a negative one. ParseRedisURL accepted it, so
the admin connection check answered 500 with a handler panic, the save
was accepted, and the next start panicked before an admin could fix it.
Since Sentinel URLs became supported, the same holds for them.

Refuse a negative pool_size in both forms with an error that names the
option, so the save answers 422 and the connection check reports a
failed check. Other negative pool options are left alone: go-redis
ignores them, so they start today.
@silo-kody

silo-kody Bot commented Oct 8, 2026 •

Copy link
Copy Markdown

Silo Kody — review complete

Review finished. Check the inline comments for findings and verify each suggestion against the code and tests.

Reviewing changes in Silo
  • Include the related issue, expected behavior, and validation steps in the PR description.
  • For API changes, describe the effect on Apple and Android clients and Jellyfin compatibility.
  • For plugin changes, identify the affected SDK contract, plugin, and catalog entry.
  • Follow this repository's AGENTS.md and CONTRIBUTING.md.
  • Request another review with @kody start-review in a PR comment.
  • React with 👍 or 👎 to give feedback on individual suggestions.
Review settings
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ❌

@coderabbitai

coderabbitai Bot commented Oct 8, 2026

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 6 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used all 4 included reviews currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: ae56edb8-589c-4acf-8c80-bef03985eb5f
📥 Commits

Reviewing files that changed from the base of the PR and between ca186fe and 9165365.

📒 Files selected for processing (2)
  • internal/config/admin_settings.go
  • internal/config/redis_url_test.go
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Quick104 Quick104 added priority: P2 Limited scope, workaround exists, or polish impact: usability Core flow broken or severely blocked labels Oct 8, 2026 — with Cursor
@macroscopeapp

macroscopeapp Bot commented Oct 8, 2026

Copy link
Copy Markdown
  • Visible effect: Saving a Redis URL with negative pool_size now produces a specific validation error in the web admin (internal/config/admin_settings.go); the Evidence section has no published link or captures. Evidence needed: before-and-after captures of the same Redis settings save with that input on desktop and phone-width web, identifying the surface and each build/commit.
  • Suggested fix: Attach those captures to the PR or publish them under Evidence with a valid evidence.siloserver.org link.

Automated check: Macroscope check run agent (gpt-6-luna). Evidence was not reviewed for correctness.

Posted via Macroscope — Visible change evidence

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

impact: usability Core flow broken or severely blocked priority: P2 Limited scope, workaround exists, or polish

Projects

None yet

Development

Successfully merging this pull request may close these issues.

pool_size=-1 in redis.url is accepted on save and panics the server at the next start

2 participants