a9054011188cb975a65a7d9767096a0ffdceb366
braney
  Mon Sep 21 17:34:46 2026 -0700
netSlurpMaxTest: cover the response size ceiling, refs #38359

The fix this defends changes nothing on any page.  Its only caller is the
hgTablesTest robot, and the failure it prevents is the process exiting from
inside carefulAlloc with nothing written to the log, so a unit test is the only
test there can be.

Four parts.  netSlurpFileMax on a plain file, both sides of the boundary,
including a ceiling exactly at the file size, which has to read it.  The same
calls under pushCarefulMemHandler, where carefulTotalAllocated() says whether
the abandoned buffer was really freed: a buffer left behind would stay counted
against the ceiling and the cap would buy one oversized page and no more.  A
matched pair of forked children on a file past the allocator ceiling, one read
capped and one not, since exit(1) from inside the allocator cannot be seen any
other way.  And htmlPageSetMaxSize reaching htmlSlurpWithCookies against a
server on the loopback interface, because the ceiling travels through a
module-wide static and that wiring can rot with no caller changing.

Backed the fix out three ways and watched each go red for its own reason.
Removing the size check fails 9 of the 18 assertions.  Keeping the check and
dropping only the dyStringFree fails 3, and only the three that count
allocation.  Reverting htmlSlurpWithCookies to a plain netSlurpFile fails 2,
and only the two that reach through htmlPage.  Recorded as sandbox-ab.

The registry row carries "-" for the release: the ticket has no target version.

diff --git src/lib/tests/expected/netSlurpMaxTest src/lib/tests/expected/netSlurpMaxTest
new file mode 100644
index 00000000000..8f88b237028
--- /dev/null
+++ src/lib/tests/expected/netSlurpMaxTest
@@ -0,0 +1,19 @@
+no ceiling reads the whole file                            ok
+ceiling above the file reads it                            ok
+ceiling exactly at the file size reads it                  ok
+ceiling one byte under returns nothing                     ok
+ceiling under the very first read returns nothing          ok
+an empty file is read, not refused                         ok
+over the ceiling under carefulAlloc, nothing comes back    ok
+the abandoned buffer is freed, not left counted            ok
+a page that is read is still held                          ok
+and is released when the caller frees it                   ok
+ten refused reads in a row leak nothing                    ok
+uncapped, the allocator still exits the process            ok
+capped, the same read returns nothing and the process lives ok
+no ceiling fetches the whole response                      ok
+ceiling exactly at the response size fetches it            ok
+ceiling one byte under aborts with the message the robot reads ok
+a ceiling well under the response aborts the same way      ok
+the ceiling can be turned back off                         ok
+0 failures