{"record":{"id":"0d44f591bd790539","repo":"vectordotdev/vector","slug":"http-status-codes-are-valid-u16-values","errorCode":null,"errorMessage":"HTTP status codes are valid u16 values","messagePattern":"HTTP status codes are valid u16 values","errorType":"panic","errorClass":null,"httpStatus":null,"severity":"error","filePath":"src/sinks/keep/config.rs","lineNumber":188,"sourceCode":"}\nasync fn healthcheck(\n    endpoint: HttpEndpoint,\n    api_key: SensitiveString,\n    client: HttpClient,\n) -> crate::Result<()> {\n    let request =\n        Request::post(endpoint.into_v1()).header(HTTP_HEADER_KEEP_API_KEY, api_key.inner());\n    let body = crate::serde::json::to_bytes(&Vec::<BoxedRawValue>::new())\n        .unwrap()\n        .freeze();\n\n    let req: Request<Bytes> = request.body(body)?;\n    let req = req.map(full_body);\n\n    let res = client.send(req).await?;\n\n    let status = StatusCode::from_u16(res.status().as_u16())\n        .expect(\"HTTP status codes are valid u16 values\");\n    let body = res.into_body().collect().await?.to_bytes();\n\n    match status {\n        StatusCode::OK => Ok(()),          // Healthcheck passed\n        StatusCode::BAD_REQUEST => Ok(()), // Healthcheck failed due to client error but is still considered valid\n        StatusCode::ACCEPTED => Ok(()),    // Consider healthcheck passed if server accepted request\n        StatusCode::UNAUTHORIZED => {\n            // Handle unauthorized errors\n            let json: serde_json::Value = serde_json::from_slice(&body[..])?;\n            let message = json\n                .as_object()\n                .and_then(|o| o.get(\"error\"))\n                .and_then(|s| s.as_str())\n                .unwrap_or(\"Token is not valid, 401 returned.\")\n                .to_string();\n            Err(message.into())\n        }\n        _ => {","sourceCodeStart":170,"sourceCodeEnd":206,"githubUrl":"https://github.com/vectordotdev/vector/blob/bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013/src/sinks/keep/config.rs#L170-L206","documentation":"During the Keep sink healthcheck, the response's http::StatusCode is converted back into the local StatusCode type via StatusCode::from_u16 and unwrapped with expect. Because res.status().as_u16() already produced a valid HTTP status code, the conversion cannot fail; the expect documents that invariant. Hitting this panic indicates a malformed internal HTTP layer rather than a server problem.","triggerScenarios":"Healthcheck receives a response whose status code, when re-parsed via StatusCode::from_u16, is invalid — only possible if the HTTP client returned a fabricated non-standard status code outside 100..=599.","commonSituations":"Buggy or patched HTTP client/proxy in front of Keep injecting invalid status lines; effectively unreachable on stock builds since hyper/reqwest already validate status codes.","solutions":["Inspect any proxies/middlewares rewriting HTTP responses between Vector and Keep.","Update the HTTP client dependency (reqwest/hyper) to a version that guarantees valid status codes.","Confirm Keep returns standard HTTP status codes (200/202/400 are handled explicitly)."],"exampleFix":null,"handlingStrategy":"fallback","validationCode":null,"typeGuard":null,"tryCatchPattern":"// keep proxies from rewriting status lines; on healthcheck failure, alert and retry\n// systemd auto-restart keeps the pipeline alive\nRestart=on-failure","preventionTips":["Keep Keep behind proxies that pass through standard HTTP status codes.","Use stock http client dependency versions.","Monitor healthcheck logs for anomalies."],"tags":["rust","panic","http","healthcheck","sink"],"backgroundTag":"internal-invariant-violation","analyzedSha":"bdb87aeaa4c4ff27c0ba643c1c77b21bf2ef4013","analyzedAt":"2026-09-16T02:53:35.741Z","contentChangedAt":"2026-09-16T02:53:35.741Z","schemaVersion":2},"datasetVersion":"2026-09-23T08:17:48.524Z"}