Problem
getDurationString (RDS, ElastiCache) and getDurationValue (EC2) silently return the 1yr duration when the term string is not "1yr", "1", "3yr", or "3":
func (c *Client) getDurationValue(term string) int64 {
if term == "3yr" || term == "3" {
return ThreeYearSeconds
}
return OneYearSeconds // silent fallback -- any unrecognized term becomes 1yr
}
This is a money-path silent fallback: a malformed term (e.g., "2yr", "invalid", or an empty string) silently issues a purchase query for a 1-year RI instead of failing loud. The convertPaymentOption functions in these same files correctly return an error on unknown values; term should follow the same pattern.
Affected files
providers/aws/services/ec2/client.go: getDurationValue
providers/aws/services/rds/client.go: getDurationString
providers/aws/services/elasticache/client.go: getDurationString
Fix
Change each function signature to return (int64/string, error) and return an explicit error for any unrecognized term (matching the convertPaymentOption pattern). Update callers (buildEC2QueryFromRec, findOfferingID preamble, getDurationString callers). Add regression tests that pass an unrecognized term and assert an error is returned before any API call.
Context
Found during adversarial review of PR #815 (findOfferingID audit). The silent fallback is pre-existing on main and out-of-scope for PR #815. Refs #515.
Problem
getDurationString(RDS, ElastiCache) andgetDurationValue(EC2) silently return the 1yr duration when the term string is not"1yr","1","3yr", or"3":This is a money-path silent fallback: a malformed term (e.g.,
"2yr","invalid", or an empty string) silently issues a purchase query for a 1-year RI instead of failing loud. TheconvertPaymentOptionfunctions in these same files correctly return an error on unknown values; term should follow the same pattern.Affected files
providers/aws/services/ec2/client.go:getDurationValueproviders/aws/services/rds/client.go:getDurationStringproviders/aws/services/elasticache/client.go:getDurationStringFix
Change each function signature to return
(int64/string, error)and return an explicit error for any unrecognized term (matching theconvertPaymentOptionpattern). Update callers (buildEC2QueryFromRec,findOfferingIDpreamble,getDurationStringcallers). Add regression tests that pass an unrecognized term and assert an error is returned before any API call.Context
Found during adversarial review of PR #815 (findOfferingID audit). The silent fallback is pre-existing on
mainand out-of-scope for PR #815. Refs #515.