Skip to content

docs(integrity): xxHash3-64 checksum covers the payload only, not format (LAB-4212) - #456

Merged
27Bslash6 merged 3 commits into
mainfrom
lab-4212-checksum-coverage
Oct 2, 2026
Merged

27Bslash6 merged 3 commits into
mainfrom
lab-4212-checksum-coverage

Conversation

@27Bslash6

Copy link
Copy Markdown
Contributor

Documents what the ByteStorage xxHash3-64 checksum actually covers: the uncompressed payload only. The envelope's format field sits outside the digest. Docs and comments only; no behaviour change.

  • docs/features/rust-serialization.md › "xxHash3-64 Integrity": names the digest's input, states that format is outside it (a rotted format passes the checksum), and points to Deserialization failed in docs/error-codes.md for how AutoSerializer validates format instead.
  • auto_serializer.py: two comments no longer call the envelope's format_id "verified"; they now say the checksum does not cover it, matching the deserialize docstring ("NEITHER copy is verified").
  • tests/unit/test_auto_serializer_mutation_and_corruption.py: a class docstring reworded the same way.

Remaining hits of grep -rn -i -E "verified[^.]{0,20}format" src/cachekit/serializers/ tests/unit/test_auto_serializer_mutation_and_corruption.py:

  • src/cachekit/serializers/auto_serializer.py:871 — "failed to decode inside a verified envelope (format=…)". "Verified" attaches to the envelope, whose payload passed the checksum. Accurate; kept.

make quick-check passes locally.

Closes LAB-4212

…mat (LAB-4212)

rust-serialization.md now names the digest's input (the uncompressed payload)
and states that the envelope's format field sits outside it, pointing to the
Deserialization failed entry for how AutoSerializer validates format. Two
comments and one test docstring no longer call format_id verified.
No behaviour change.
@coderabbitai

coderabbitai Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 59 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: Repository: cachekit-io/cachekit-py/.coderabbit.yaml

Review profile: ASSERTIVE

Plan: Advanced

Run ID: a5d5c4b6-cb5d-485b-bfe3-304f59334ca3

📥 Commits

Reviewing files that changed from the base of the PR and between b9ad394 and 94b4b4c.

📒 Files selected for processing (3)
  • docs/features/rust-serialization.md
  • src/cachekit/serializers/auto_serializer.py
  • tests/unit/test_auto_serializer_mutation_and_corruption.py
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@kodus-27b

kodus-27b Bot commented Oct 2, 2026 •

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

kodus-27b[bot]
kodus-27b Bot previously approved these changes Oct 2, 2026
…AB-4212)

The xxHash3-64 section now says which values carry the envelope checksum: integrity-off values carry none, and the NumPy and Arrow routes use their own prefix. The format sentence now states what AutoSerializer accepts and links what still gets through. Comment and docstring wording trimmed. No behaviour change.
@kodus-27b

kodus-27b Bot commented Oct 2, 2026

Copy link
Copy Markdown

Code Review Completed! 🔥

The code review was successfully completed based on your current configurations.

Kody Guide: Usage and Configuration
Interacting with Kody
  • Request a Review: Ask Kody to review your PR manually by adding a comment with the `@kody start-review` command at the root of your PR.

  • Provide Feedback: Help Kody learn and improve by reacting to its comments with a 👍 for helpful suggestions or a 👎 if improvements are needed.

Providing Context (Files & MCPs)

Add these hints in your PR description (or a comment) to unlock deeper checks:

  • Ticket / Acceptance Criteria: `Refs: ABC-123` (Linear/Jira/Asana/ClickUp/Trello) or a direct ticket link.
  • Bugfix Validation: a Sentry/Datadog/Bugsnag event link (or paste the stack trace/error message).
  • Endpoint Risk: mention the route (e.g., `POST /api/payments`) or controller/action name.
  • Attach a repo file as context: use an explicit marker like `@file:docs/guide.mdx#L10-L50` (replace with your real path).
  • API Contract Docs: include `@file:openapi.yaml` or `@file:swagger.json` when changing routes/schemas.
  • Definition of Done / Standards: include `@file:DOD.md` or `@file:CONTRIBUTING.md` if your repo has them.
  • Design System Source of Truth: include `@file:ui/index.ts` (replace with your DS entrypoint path).
  • Feature Flags: include the flag key/name and `@file:flags.ts` / `@file:config.json` (and optionally the PostHog flag name).
  • Edge/CDN Rules: link the Cloudflare rule/zone or describe the intended redirect/header behavior.
  • Attach an MCP tool output: use `@mcp<provider|tool>` (replace with an installed MCP provider + tool, e.g., `@mcp<sentry|events.search>`).
Current Kody Configuration
Review Options

The following review options are enabled or disabled:

Options Enabled
Bug ✅
Performance ✅
Security ✅
Business Logic ✅

Access your configuration settings here.

@codecov

codecov Bot commented Oct 2, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ All tests successful. No failed tests found.

📢 Thoughts on this report? Let us know!

@27Bslash6
27Bslash6 merged commit 1145202 into main Oct 2, 2026
36 checks passed
@27Bslash6
27Bslash6 deleted the lab-4212-checksum-coverage branch October 2, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant