Skip to content

fix(policy): narrow authorization attribute lookups - #3986

Merged
jakedoublev merged 2 commits into
mainfrom
codex/authz-perf/targeted-policy
Oct 2, 2026
Merged

jakedoublev merged 2 commits into
mainfrom
codex/authz-perf/targeted-policy

Conversation

@strantalis

@strantalis strantalis commented Sep 5, 2026 •

Copy link
Copy Markdown
Member

GetEntitleableAttributesByFqns currently wraps the broad attribute lookup and discards most of its result. Give it a dedicated SQL path for requested values, rule and namespace identity, and ordered active hierarchy values. Keep the targeted subject-mapping query. The attribute query reads no grants, keys, or resource mappings.

Preserve missing/inactive-value errors, normalization, hierarchy order, and traversal. No API or migration change.

With the merged scale fixture, this PR alone reduced p95 at 50 concurrent requests from 8.72 seconds to 180 ms. All 800 requests passed on each implementation. Caching and experimental features were disabled. Comparison details: #3991.

Layer 1 of 6, rebased on main at f2635158 with #3983's tests. Next: #3987.

Verified: PostgreSQL integration tests, service race suite, SQL generation, formatting, and lint for the stack diff. Full repository check limitations: #3991.

Summary by CodeRabbit

  • Bug Fixes
    • Improved entitlement attribute lookups for requested fully qualified names, including case-insensitive matching and duplicate requests.
    • Hierarchical attributes now include active values while correctly distinguishing explicitly inactive values from unknown ones.
    • Lookups return not-found errors for inactive attribute definitions and missing requested names.

@coderabbitai

coderabbitai Bot commented Sep 5, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 46 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: f844165d-126d-4cdc-ab1e-bb2cc1a7299c

📥 Commits

Reviewing files that changed from the base of the PR and between 7cf27e4 and 5113435.

📒 Files selected for processing (3)
  • service/integration/attributes_test.go
  • service/policy/db/entitleable_attributes.sql.go
  • service/policy/db/queries/entitleable_attributes.sql

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Repository UI

Review profile: ASSERTIVE

Plan: Advanced

Run ID: 1a6cf39d-e559-4470-bbc4-80e4ed72431a

📥 Commits

Reviewing files that changed from the base of the PR and between f263515 and 7cf27e4.

📒 Files selected for processing (5)
  • service/integration/attributes_test.go
  • service/policy/db/attribute_fqn.go
  • service/policy/db/entitleable_attributes.go
  • service/policy/db/entitleable_attributes.sql.go
  • service/policy/db/queries/entitleable_attributes.sql

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

GetEntitleableAttributesByFqns now uses a dedicated resolver and database query. The query selects matching active definitions, requested values, and active hierarchy values. Integration tests cover normalized FQNs, inactive values and definitions, traversal, empty requests, and missing FQNs.

Changes

Entitleable attribute lookup

Layer / File(s) Summary
Attribute query and row mapping
service/policy/db/queries/entitleable_attributes.sql, service/policy/db/entitleable_attributes.sql.go
The query selects matching active definitions and requested values, plus other active values for hierarchy definitions. The generated wrapper scans the definition, namespace, rule, and value fields.
FQN resolution and lookup coverage
service/policy/db/entitleable_attributes.go, service/policy/db/attribute_fqn.go, service/integration/attributes_test.go
The resolver normalizes requested FQNs, rejects inactive requested values, allows missing values when traversal is enabled, and returns ErrNotFound for other missing values. Integration tests cover these outcomes and empty requests.

Priority: ➖ Normal

Estimated code review effort: 3 (Moderate) | ~20 minutes

Change: Bug fix

Suggested reviewers: jakedoublev

Merge Risk: ⚪ Minimal · up to 7cf27

The targeted lookup preserves the documented normalization, inactive-value, traversal, and hierarchy behavior. No concrete merge-blocking issue remains; merge after normal checks pass.

Security Architecture Review

Security architecture risk: ⚪ Minimal · up to 7cf27

The narrower lookup preserves the inspected authorization controls and avoids fetching grants and keys that its response does not use. No material security risk introduced or worsened by this change was identified.

Retained concerns
No architecture-level concerns identified.

Security review details

Security Blast Radius

  • inferred — The inspected security-relevant exposure is authorization evaluation for supplied resource attribute FQNs. Hierarchy expansion remains confined to values belonging to the selected definitions; this change does not introduce grant, key, or infrastructure authority into the lookup.

Trust Boundaries and Controls

  • observed — Request-derived FQNs are lowercased and passed as bound query parameters. Selection requires active namespaces and definitions. Explicitly inactive requested values are rejected rather than treated as traversal misses, and authorization independently rejects any traversal-only entry lacking a value ID.
🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and concisely describes the main change: narrowing policy authorization attribute lookups through a dedicated lookup path.
Docstring Coverage ✅ Passed No functions found in the changed files to evaluate docstring coverage. Skipping docstring coverage check. Docstring coverage is scoped to functions touched by this diff. Analyzed 0 functions across 4…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

A rabbit checks the FQNs in a row,
Active paths show where values go.
Inactive leaves are turned away,
Missing trails may still allow the way.
The burrow’s lookup rests in order today.

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added comp:db DB component comp:policy Policy Configuration ( attributes, subject mappings, resource mappings, kas registry) size/m labels Sep 5, 2026
@strantalis strantalis changed the title codex/authz perf/targeted policy perf(policy): narrow authorization attribute lookups Sep 5, 2026
@strantalis strantalis changed the title perf(policy): narrow authorization attribute lookups fix(policy): narrow authorization attribute lookups Sep 5, 2026
@github-actions

github-actions Bot commented Sep 5, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 238.731867ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 130.726931ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 413.145896ms
Throughput 242.05 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 41.437711459s
Average Latency 413.643254ms
Throughput 120.66 requests/second

Comment thread service/policy/db/queries/entitleable_attributes.sql
Comment thread service/policy/db/queries/entitleable_attributes.sql
Comment thread service/policy/db/attribute_fqn.go
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 222.808841ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 129.807265ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 410.135225ms
Throughput 243.82 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 44.110016217s
Average Latency 440.386176ms
Throughput 113.35 requests/second

Signed-off-by: strantalis <strantalis@virtru.com>
@strantalis
strantalis force-pushed the codex/authz-perf/targeted-policy branch from a3ae767 to 7cf27e4 Compare October 1, 2026 21:03
@strantalis
strantalis removed this pull request from stack #3992 October 1, 2026 21:07
@strantalis
strantalis added this pull request to stack #4131 October 1, 2026 21:07
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 184.962171ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 102.815221ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 369.426449ms
Throughput 270.69 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 37.147329931s
Average Latency 370.510137ms
Throughput 134.60 requests/second

@strantalis

Copy link
Copy Markdown
Member Author

@coderabbitai review

@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
✅ Action performed

Review finished.

Note: CodeRabbit is an incremental review system and does not re-review already reviewed commits. This command is applicable only when automatic reviews are paused.

Signed-off-by: strantalis <strantalis@virtru.com>
@strantalis
strantalis marked this pull request as ready for review October 1, 2026 22:14
@strantalis
strantalis requested review from a team as code owners October 1, 2026 22:14
@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Benchmark authorization.GetDecisions Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 173.644984ms

Benchmark authorization.v2.GetMultiResourceDecision Results:

Metric Value
Approved Decision Requests 1000
Denied Decision Requests 0
Total Time 102.441914ms

Benchmark Statistics

Name № Requests Avg Duration Min Duration Max Duration

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 400.869236ms
Throughput 249.46 requests/second

TDF3 Benchmark Results:

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 40.284680769s
Average Latency 402.035406ms
Throughput 124.12 requests/second

@github-actions

github-actions Bot commented Oct 1, 2026

Copy link
Copy Markdown
Contributor

⚠️ Govulncheck found vulnerabilities ⚠️

The following modules have known vulnerabilities:

  • otdfctl
  • service
  • tests-bdd

See the workflow run for details.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The optimized path preserves existing behavior and is covered by focused integration tests.

Review effort: Balanced
Findings: None

What changed in this PR

Introduces a targeted policy lookup for entitlement authorization, avoiding unnecessary grants, keys, and resource mappings.

Changes:

  • Adds an optimized SQL query for requested and hierarchical values.
  • Preserves normalization, traversal, ordering, and inactive-value handling.
  • Expands integration coverage for edge cases.
File Description
service/​policy/​db/​queries/​entitleable_attributes.sql Defines the targeted lookup.
service/​policy/​db/​entitleable_attributes.sql.go Adds generated sqlc bindings.
service/​policy/​db/​entitleable_attributes.go Resolves and hydrates entitlement values.
service/​policy/​db/​attribute_fqn.go Uses the optimized resolver.
service/​integration/​attributes_test.go Tests normalization, hierarchy, traversal, and inactive values.
Files not reviewed (1)
  • service/policy/db/entitleable_attributes.sql.go: Generated file

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@strantalis

Copy link
Copy Markdown
Member Author

@jakedoublev I am comfortable with this pr.

Comment thread service/policy/db/entitleable_attributes.go
Comment thread service/policy/db/entitleable_attributes.go
@jakedoublev
jakedoublev added this pull request to the merge queue Oct 2, 2026
Merged via the queue into main with commit 52f2ece Oct 2, 2026
49 checks passed
@jakedoublev
jakedoublev deleted the codex/authz-perf/targeted-policy branch October 2, 2026 19:44
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

comp:db DB component comp:policy Policy Configuration ( attributes, subject mappings, resource mappings, kas registry) size/m

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants