fix(core): DSPX-4999 restore database and external-core tracing - #4122
Conversation
Signed-off-by: strantalis <strantalis@virtru.com>
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. 🧰 Additional context used📚 Code guidelines (1)No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Repository UI Review profile: ASSERTIVE Plan: Advanced Run ID: ⛔ Files ignored due to path filters (1)
📒 Files selected for processing (6)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe change adds PostgreSQL and external SDK client tracing, documents tracing coverage, and updates tracer shutdown so initialization-context cancellation does not cancel shutdown. ChangesTracing updates
Priority: ⬇️ Low Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to This change restores database and external-core tracing and lets tracer shutdown flush spans after the initialization context is canceled. No concrete merge-blocking risk was found. Deployed trace linkage was not verified. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to Tracing expands the operational data sent to configured collectors or files. Existing export enablement, authentication, and transport choices remain, and shutdown now preserves flushing after cancellation. Exact database trace payloads and deployment access controls remain unverified. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
Resilience and Maintainability Implications
Hardening Proposals
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 40.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 5 functions across 4 files. (2 skipped: 2 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit traced the database trail, Comment |
Benchmark results, click to expandBenchmark authorization.GetDecisions Results:
Benchmark authorization.v2.GetMultiResourceDecision Results:
Benchmark Statistics
Bulk Benchmark Results
TDF3 Benchmark Results:
|
|
Proposed Changes
Restore missing runtime tracing for DSPX-4999:
otelpgxto the shared database pool so recorded requests include SQL and pool-acquisition spans. Bind parameters remain excluded.Tracing remains controlled by
server.trace.enabled. SQL timings include reading rows; they do not isolate database execution from result transfer.Related: #3307 already proposes SQL tracing alongside broader authorization instrumentation. This PR overlaps its database portion and adds the external-core and shutdown fixes on current main. #3722 covers separate CLI tracing work.
Testing Instructions
Passed:
make fmt, service build, race tests fortracing,pkg/db, andpkg/server, SDK README tests, diff-scoped lint, andgit diff --check. The cancellation regression fails before the fix and passes after it.Full
make testand service-wide tests require the unavailable Keycloak/Docker/platform stack. Fullmake lintreports existing findings in unchanged code; a separate scoped vulnerability check flags the installed Go 1.26.3 standard library. No unrelated fixes included.After deployment, verify SQL/pool spans under
ListAttributes, trace continuity to an external core, and no export with tracing disabled.Checklist
Summary by CodeRabbit
server.trace.enabled.