Skip to content

fix(triggers): surface listener panics as errors instead of dropping events (EN-1222) - #185

Closed
flemzord wants to merge 1 commit into
mainfrom
fix/listener-panic-handling
Closed

fix(triggers): surface listener panics as errors instead of dropping events (EN-1222)#185
flemzord wants to merge 1 commit into
mainfrom
fix/listener-panic-handling

Conversation

@flemzord

Copy link
Copy Markdown
Member

Problem (H2 — HIGH)

handleMessage had an unnamed error return:

defer func() {
    if e := recover(); e != nil { fmt.Println(e); debug.PrintStack() }
}()

Recovering a panic therefore left the return value nil, so watermill ACKed the message. And getWorkflowIDFromEvent deliberately panic()s on (un)marshal failures (e.g. a SAVED_PAYMENT payload whose id is not a string). Net effect: a single malformed event is permanently dropped, with only a stdout print — no metric, no redelivery.

Fix

  • getWorkflowIDFromEvent returns an error instead of panicking; handleMessage wraps and returns it.
  • handleMessage uses a named return so a recovered panic is converted into a returned error (NACK → redelivery / DLQ) and logged with its stack via the structured logger.

Test

TestHandleMessage/malformed payment payload returns an error instead of being dropped — a SAVED_PAYMENT with a numeric id now returns an error.

Severity: HIGH.

Note: touches internal/triggers/listener.go which #184 also edits (different regions). The two are independent; merging both may need a trivial conflict resolution.

…events

handleMessage had an unnamed error return, so its recover() returned nil
and watermill ACKed the message. getWorkflowIDFromEvent deliberately
panicked on (un)marshal failures (e.g. a SAVED_PAYMENT payload whose id is
not a string), so a malformed event was permanently dropped with only a
stdout print.

- getWorkflowIDFromEvent now returns an error instead of panicking.
- handleMessage uses a named return so a recovered panic is converted into
  a returned error (NACK + redelivery/DLQ) and logged with its stack via
  the structured logger.

Adds a test asserting a malformed payment payload returns an error.

Note: overlaps internal/triggers/listener.go with #184 (idempotence); the
two are independent and may need a trivial merge.
@coderabbitai

coderabbitai Bot commented Jun 11, 2026

Copy link
Copy Markdown

Warning

Review limit reached

@flemzord, we couldn't start this review because you've reached your PR review rate limit.

More reviews will be available in 27 minutes and 19 seconds. Learn how PR review limits work.

Your organization has run out of usage credits. Purchase more credits in the billing tab to continue.

⌛ How to resolve this issue?

After more reviews become available, a review can be triggered using the @coderabbitai review command as a PR comment. Alternatively, push new commits to this PR.

We recommend that you space out your commits to avoid hitting the rate limit.

🚦 How do rate limits work?

CodeRabbit enforces hourly rate limits for each developer per organization.

Our paid plans include higher PR review limits than trial, open-source, and free plans. In all cases, reviews become available again over time. During sustained high-volume PR review activity, CodeRabbit may temporarily slow when the next review becomes available.

Please see our Fair Usage Limits Policy for further information.

ℹ️ Review info
⚙️ Run configuration

Configuration used: Organization UI

Review profile: CHILL

Plan: Pro

Run ID: 50203eea-ab70-4103-88bb-fc7855e1ed95

📥 Commits

Reviewing files that changed from the base of the PR and between 271bf8d and 0c7ef38.

📒 Files selected for processing (2)
  • internal/triggers/listener.go
  • internal/triggers/listener_test.go
✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch fix/listener-panic-handling

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@flemzord

flemzord commented Jun 11, 2026

Copy link
Copy Markdown
Member Author

Tracked in Jira: EN-1222 (Epic EN-1217).

@flemzord flemzord changed the title fix(triggers): surface listener panics as errors instead of dropping events fix(triggers): surface listener panics as errors instead of dropping events (EN-1222) Jun 11, 2026
@flemzord

flemzord commented Aug 5, 2026

Copy link
Copy Markdown
Member Author

Superseded by #199, which consolidates this change with the related reliability and safety fixes on top of the current main branch.

@flemzord flemzord closed this Aug 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant