Repository navigation
Conversation
Signed-off-by: Chris Reed <creed@virtru.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (7)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughKey rotation now rejects keys that are not ACTIVE and updates a key only when its persisted status is ACTIVE. Tests cover repeated, stale-state, and concurrent rotation attempts, along with base-key selection. ChangesKey rotation
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~20 minutes Change: Bug fix Suggested reviewers: Merge Risk: ⚪ Minimal · up to Key rotation now rejects non-ACTIVE keys and updates a key's status only while it is ACTIVE. Concurrent requests therefore produce a single successor. No concrete merge-blocking risk remains in the supplied evidence. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
Full details: Docstring CoverageExplanation Docstring coverage is 0.00% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 1 functions across 6 files. (1 skipped: 1 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit checks the key status right, Comment |
Benchmark results, click to expandBulk Benchmark Results
TDF3 Benchmark Results
|
Signed-off-by: Chris Reed <creed@virtru.com>
Benchmark results, click to expandBulk Benchmark Results
TDF3 Benchmark Results
|
Signed-off-by: Chris Reed <creed@virtru.com>
Benchmark results, click to expandBulk Benchmark Results
TDF3 Benchmark Results
|
Signed-off-by: Chris Reed <creed@virtru.com>
Benchmark results, click to expandBulk Benchmark Results
TDF3 Benchmark Results
|
Signed-off-by: Chris Reed <creed@virtru.com>
Benchmark results, click to expandBulk Benchmark Results
TDF3 Benchmark Results
|
|
Proposed Changes
Require an ACTIVE source before key rotation, returning a logged
FailedPreconditionerror (key must be ACTIVE). Atomically enforce that status when updating the source so concurrent requests produce one successor; a stale request returns the existingNotFounderror. Preserve key metadata and mapping/base-key transfers.Checklist
Testing Instructions
Race-enabled tests verify non-base-key rotation, rejection of a rotated source, and a single concurrent successor with no loser record. All 13 CLI rotation BATS cases pass, including the early error and backend logging. Focused unit tests and diff lint pass. Full checks encounter existing lint/vulnerability findings and a round-trip suite requiring a separately provisioned platform.
Summary by CodeRabbit