Fleet versions
- Discovered: rc-patch-fleet-v4.92.2 (dc3a236)
- Reproduced: rc-minor-fleet-v4.93.0 (9d1f267)
Web browser and operating system: N/A (API)
💥 Actual behavior
GET /api/v1/fleet/software/titles without per_page returns every software title in one response. On a load test with 418,126 titles that took 96–101 s and 321–376 MB, right at Fleet's own 100 s write timeout.
🛠️ Expected behavior
The response is bounded like GET /api/v1/fleet/software/versions, which returns at most 10,000 versions without pagination parameters since #47755.
🧑💻 Steps to reproduce
These steps:
- Use an instance with a large software inventory. Reproduced on a load test with 100K osquery-perf hosts and 418,126 software titles.
GET /api/v1/fleet/software/titles (no per_page).
- 200 after ~100 s, with all 418,126 titles (~350 MB).
🕯️ More info (optional)
Without per_page, list options fall back to fleet.DefaultPerPage (1,000,000; server/fleet/app.go:2153). #47755 added a 10,000 cap for /software/versions only (server/service/software.go:76). In the same state before that fix, /software/versions without per_page returned 502.
Fleet versions
Web browser and operating system: N/A (API)
💥 Actual behavior
GET /api/v1/fleet/software/titleswithoutper_pagereturns every software title in one response. On a load test with 418,126 titles that took 96–101 s and 321–376 MB, right at Fleet's own 100 s write timeout.🛠️ Expected behavior
The response is bounded like
GET /api/v1/fleet/software/versions, which returns at most 10,000 versions without pagination parameters since #47755.🧑💻 Steps to reproduce
These steps:
GET /api/v1/fleet/software/titles(noper_page).🕯️ More info (optional)
Without
per_page, list options fall back tofleet.DefaultPerPage(1,000,000;server/fleet/app.go:2153). #47755 added a 10,000 cap for/software/versionsonly (server/service/software.go:76). In the same state before that fix,/software/versionswithoutper_pagereturned 502.