Skip to content

ARCH-01: Azure purchase bodies send non-canonical reservedResourceType literals (SqlDatabase, SqlDW) #1189

Description

@cristim

Severity: P2 (downgraded from P1 by the verifier). Confidence: medium.

Affected files:

  • providers/azure/services/database/client.go:321
  • providers/azure/services/synapse/client.go:271
  • providers/azure/recommendations.go:407
  • providers/azure/services/compute/exchange.go:146

Evidence:
database/client.go:321 builds the calculatePrice/purchase body with "reservedResourceType": "SqlDatabase" and synapse/client.go:271 with "SqlDW". The vendored armreservations v1.1.0 enum defines ReservedResourceTypeSQLDatabases = "SqlDatabases" and ReservedResourceTypeSQLDataWarehouse = "SqlDataWarehouse"; neither hand-written variant appears in PossibleReservedResourceTypeValues(). The codebase's own inbound Advisor mapping agrees with the plural form (case "sqldatabases"), and the compute client correctly uses the SDK constant for reads. Per known-issues #731, non-VM Azure purchases have been 403-blocked, so these values have plausibly never been exercised live.

Impact:
When the #731 role fix lands, Azure SQL Database / Synapse reservation calculatePrice calls will likely be rejected with a 400 for an invalid reservedResourceType, breaking the purchase path for those services. Repeats the exact failure mode of PR #1047 ("MEMORY_MB" instead of SDK "MEMORY") flagged in the project's memory garden.

Recommendation:
Replace the raw literals with string(armreservations.ReservedResourceTypeSQLDatabases) / ReservedResourceTypeSQLDataWarehouse; audit "SearchService" and managedredis "RedisCache" against the live catalog; add a unit test asserting every purchase body's reservedResourceType is a member of PossibleReservedResourceTypeValues(). Also check the singular 'SqlDatabase' Advisor filter at database/client.go:173.

Verifier verdict: downgraded to P2 - fully verified factually, but the failure mode is fail-loud and side-effect-free (calculatePrice rejects before money moves) and the path is unreachable live today, so it is a latent within-months bug, not P1.

Source: docs/reviews/codebase-review-2026-06-10.md (automated multi-dimension code review, adversarially verified for P1/P2)

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    effort/sHoursimpact/fewLimited audiencepr-createdA PR has been opened for this issue (dedup guard for the auto-PR loop)priority/p2Backlog-worthyseverity/mediumModerate harmtriagedItem has been triagedtype/choreMaintenance / non-user-visibleurgency/this-quarterWithin the quarter

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions