Skip to content

fix(providers/aws): getDurationString/getDurationValue silently fallback to 1yr on unrecognized term #1266

Description

@cristim

Problem

getDurationString (RDS, ElastiCache) and getDurationValue (EC2) silently return the 1yr duration when the term string is not "1yr", "1", "3yr", or "3":

func (c *Client) getDurationValue(term string) int64 {
    if term == "3yr" || term == "3" {
        return ThreeYearSeconds
    }
    return OneYearSeconds // silent fallback -- any unrecognized term becomes 1yr
}

This is a money-path silent fallback: a malformed term (e.g., "2yr", "invalid", or an empty string) silently issues a purchase query for a 1-year RI instead of failing loud. The convertPaymentOption functions in these same files correctly return an error on unknown values; term should follow the same pattern.

Affected files

  • providers/aws/services/ec2/client.go: getDurationValue
  • providers/aws/services/rds/client.go: getDurationString
  • providers/aws/services/elasticache/client.go: getDurationString

Fix

Change each function signature to return (int64/string, error) and return an explicit error for any unrecognized term (matching the convertPaymentOption pattern). Update callers (buildEC2QueryFromRec, findOfferingID preamble, getDurationString callers). Add regression tests that pass an unrecognized term and assert an error is returned before any API call.

Context

Found during adversarial review of PR #815 (findOfferingID audit). The silent fallback is pre-existing on main and out-of-scope for PR #815. Refs #515.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions