Skip to content

fix(authz): scope uncached direct decisions to resource policy - #4193

Merged
strantalis merged 3 commits into
codex/authz-uncached/policy-readfrom
codex/authz-uncached/direct-decisions
Oct 8, 2026
Merged

strantalis merged 3 commits into
codex/authz-uncached/policy-readfrom
codex/authz-uncached/direct-decisions

Conversation

@strantalis

@strantalis strantalis commented Oct 7, 2026 •

Copy link
Copy Markdown
Member

Proposed Changes

With caching disabled, enabling direct entitlements currently loads every attribute and subject mapping before a decision. Fetch the policy referenced by the request's resources through the PDP policy read from #4192.

Cached decisions and entitlement enumeration retain their full-policy path. Registered resources and obligations still load during construction.

Testing Instructions

Authorization race tests and changed-code lint pass, covering attribute rules, missing/inactive values, action mismatch, and cache/enumeration behavior. The previous rebased stack's CI scale run completed all 800 direct requests with zero failures: at concurrency 50, median 233 ms and p95 289 ms. The baseline timed out all 200 requests at that concurrency. These are individual CI runs; the RPC simplification still needs a fresh scale measurement.

@strantalis
strantalis added this pull request to stack #4195 October 7, 2026 15:44
@coderabbitai

coderabbitai Bot commented Oct 7, 2026

Copy link
Copy Markdown

Important

Draft PR not reviewed

Draft PRs are not automatically reviewed by default.

  • Trigger a manual review

To automatically review draft PRs, update your CodeRabbit configuration:

reviews:
  auto_review:
    drafts: true
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions github-actions Bot added the size/m label Oct 7, 2026
@strantalis strantalis changed the title codex/authz uncached/direct decisions perf(authz): scope uncached direct decisions to resource policy Oct 7, 2026
@strantalis strantalis changed the title perf(authz): scope uncached direct decisions to resource policy fix(authz): scope uncached direct decisions to resource policy Oct 7, 2026
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 338.916396ms
Throughput 295.06 requests/second

TDF3 Benchmark Results

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 33.604128276s
Average Latency 335.213357ms
Throughput 148.79 requests/second

@strantalis
strantalis force-pushed the codex/authz-uncached/direct-decisions branch from 6c575d0 to 51bb875 Compare October 7, 2026 18:22
@strantalis
strantalis force-pushed the codex/authz-uncached/policy-read branch from 03a0eed to 3bd2edc Compare October 7, 2026 18:22
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

X-Test Failure Report

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 428.22348ms
Throughput 233.52 requests/second

TDF3 Benchmark Results

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 44.145199999s
Average Latency 440.254381ms
Throughput 113.26 requests/second

Signed-off-by: strantalis <strantalis@virtru.com>
Signed-off-by: strantalis <strantalis@virtru.com>
Signed-off-by: strantalis <strantalis@virtru.com>
@strantalis
strantalis force-pushed the codex/authz-uncached/direct-decisions branch from 51bb875 to 675bbfc Compare October 7, 2026 19:21
@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

X-Test Failure Report

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 454.268903ms
Throughput 220.13 requests/second

TDF3 Benchmark Results

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 43.888138462s
Average Latency 438.0023ms
Throughput 113.93 requests/second

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor
Benchmark results, click to expand

Bulk Benchmark Results

Metric Value
Total Decrypts 100
Successful Decrypts 100
Failed Decrypts 0
Total Time 433.458922ms
Throughput 230.70 requests/second

TDF3 Benchmark Results

Metric Value
Total Requests 5000
Successful Requests 5000
Failed Requests 0
Concurrent Requests 50
Total Time 49.802147562s
Average Latency 496.944933ms
Throughput 100.40 requests/second

@github-actions

github-actions Bot commented Oct 7, 2026

Copy link
Copy Markdown
Contributor

⚠️ Govulncheck found vulnerabilities ⚠️

The following modules have known vulnerabilities:

  • otdfctl
  • service
  • tests-bdd

See the workflow run for details.

@strantalis
strantalis removed this pull request from stack #4195 October 8, 2026 14:08
@strantalis
strantalis merged commit 675bbfc into codex/authz-uncached/policy-read Oct 8, 2026
72 of 81 checks passed
@strantalis
strantalis deleted the codex/authz-uncached/direct-decisions branch October 8, 2026 14:08
@strantalis

Copy link
Copy Markdown
Member Author

This change is now included in #4192. GitHub automatically marked this PR merged into its parent branch during consolidation. #4192 remains the combined PR targeting main and includes the policy read, direct-entitlement and dynamic-mapping optimizations, and their tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant