Skip to content

Software titles API: request without per_page returns every title (418K titles in ~100 s) #54486

Description

@AndreyKizimenko

Fleet versions

  • Discovered: rc-patch-fleet-v4.92.2 (dc3a236)
  • Reproduced: rc-minor-fleet-v4.93.0 (9d1f267)

Web browser and operating system: N/A (API)


💥 Actual behavior

GET /api/v1/fleet/software/titles without per_page returns every software title in one response. On a load test with 418,126 titles that took 96–101 s and 321–376 MB, right at Fleet's own 100 s write timeout.

🛠️ Expected behavior

The response is bounded like GET /api/v1/fleet/software/versions, which returns at most 10,000 versions without pagination parameters since #47755.

🧑‍💻 Steps to reproduce

These steps:

  • Have been confirmed to consistently lead to reproduction in multiple Fleet instances.
  • Describe the workflow that led to the error, but have not yet been reproduced in multiple Fleet instances.
  1. Use an instance with a large software inventory. Reproduced on a load test with 100K osquery-perf hosts and 418,126 software titles.
  2. GET /api/v1/fleet/software/titles (no per_page).
  3. 200 after ~100 s, with all 418,126 titles (~350 MB).

🕯️ More info (optional)

Without per_page, list options fall back to fleet.DefaultPerPage (1,000,000; server/fleet/app.go:2153). #47755 added a 10,000 cap for /software/versions only (server/service/software.go:76). In the same state before that fix, /software/versions without per_page returned 502.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    #g-supply-chainSupply Chain product groupbugSomething isn't working as documented~released bugThis bug was found in a stable release.

    Type

    No type

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions