Skip to content

test(tls): cover exact peer certificate limits - #336

Open
seonghobae wants to merge 3 commits into
mainfrom
test/tls-certificate-exact-limits
Open

seonghobae wants to merge 3 commits into
mainfrom
test/tls-certificate-exact-limits

Conversation

@seonghobae

@seonghobae seonghobae commented Sep 30, 2026 •

Copy link
Copy Markdown
Contributor

Scope

  • Accept peer certificate chains exactly at the configured count and total-byte ceilings.
  • Keep the existing over-limit rejection assertions and record the regression in the changelog.

Verification

  • cargo fmt --all -- --check
  • cargo test --locked --workspace --all-targets --offline
  • cargo clippy --locked --workspace --all-targets --offline -- -D warnings
  • RUSTDOCFLAGS="-D warnings" cargo doc --locked --workspace --no-deps --offline
  • python3 -m unittest discover -s tests -p "test_*.py" (152 passed)

No production behavior or TLS authority changes. Protected-main status remains unchanged until required exact-head checks and review pass.

🤖 Generated with Claude Code

Summary by CodeRabbit

  • 테스트
    • TLS 신뢰 루트, 정책 제한, 인증서 체인의 경계값 검증을 보강했습니다. 허용된 최대값은 수용하고 한도를 초과하는 값은 거부하는 동작을 확인합니다.
    • 신뢰 루트의 중복 제거와 순서에 무관한 해시, ALPN 및 인증서 유효 기간의 제한 검증을 추가했습니다.
  • 문서
    • TLS 정책 회귀 테스트의 경계값과 검증 기준을 문서화했습니다.

Co-Authored-By: Claude Code <noreply@anthropic.com>
@coderabbitai

coderabbitai Bot commented Sep 30, 2026 •

Copy link
Copy Markdown

Review in Change Stack →

Navigate logical layers of code changes, visualize relationships, and explore their blast radius.

🧰 Additional context used
📚 Code guidelines (1)
AGENTS.md — auto-discovered

No actionable comments were generated in the recent review. 🎉

ℹ️ Recent review info
⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: e15ae32b-6215-4d94-a058-6098961cbccd
📥 Commits

Reviewing files that changed from the base of the PR and between 87c4daa and 6dbd71a.

📒 Files selected for processing (5)
  • CHANGELOG.md
  • crates/originweave-tls/src/handshake.rs
  • crates/originweave-tls/tests/policy_contract.rs
  • crates/originweave-tls/tests/tls_policy_literal_bounds.rs
  • docs/TEST_STRATEGY.md

Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review.


📝 Walkthrough

Walkthrough

TLS 정책, 신뢰 루트, 서버 인증서 체인의 경계값을 확인하는 회귀 테스트를 추가했습니다. 관련 테스트 전략과 변경 기록도 갱신했습니다. 본 변경에는 프로덕션 TLS 동작 변경이 포함되지 않습니다.

Changes

TLS 경계 테스트

Layer / File(s) Summary
TLS 정책 한계 검증
crates/originweave-tls/tests/policy_contract.rs, crates/originweave-tls/tests/tls_policy_literal_bounds.rs, docs/TEST_STRATEGY.md, CHANGELOG.md
식별자, 핸드셰이크 제한 시간, 리프 인증서 유효 기간, ALPN의 최대값 수용과 인접 초과값 거부를 검증합니다. 테스트 전략과 변경 기록에도 해당 경계 검증 내용을 추가했습니다.
신뢰 루트 경계와 정규화
crates/originweave-tls/tests/policy_contract.rs
중복 입력의 정규화, 최대 개수의 고유 루트 수용, 입력 순서와 무관한 해시, 257개 루트 거부를 검증합니다. 최대 바이트 입력이 DER 검증 단계까지 도달하는지도 확인합니다.
서버 인증서 체인 경계
crates/originweave-tls/src/handshake.rs
인증서 개수와 전체 바이트가 각각 설정된 최대값과 같은 경우를 수용하는 검사를 추가했습니다.

Priority: ⬇️ Low

Estimated code review effort: 2 (Simple) | ~10 minutes

Change: Other

Merge Risk: ⚪ Minimal · up to 6dbd7

No code-review blocker was identified in these changes. Merge remains subject to the required exact-head checks, including the reported failing CodeQL check.

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed 제목은 피어 인증서 체인의 설정된 한계값을 정확히 허용하는 회귀 테스트라는 주요 변경 사항을 명확히 설명합니다.
Docstring Coverage ✅ Passed Docstring coverage is 88.89% which is sufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 9 functions across 3 files. (2 skipped: 2 u…
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.
✨ Finishing Touches 💡 1
🛠️ Fix failing CI checks 💡
  • Commit to this branch
  • Create a new PR
📝 Generate docstrings
  • Commit to this branch
  • Create a new PR
🧪 Generate unit tests (beta)
  • Commit to this branch
  • Create a new PR
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

Copy link
Copy Markdown
Contributor Author

Admission repair for exact head ae95cbf2e37de5c9d9f0ebbe06e4dd2666212fc0:

This Ready PR still has a concrete merge blocker: terminal workflow: CodeQL PR 36662360843=failure. Converted to Draft/Proposed so review admission does not imply merge readiness while preserving the full branch delta. Acceptance: repair the cited exact-head failure/topology or complete the declared predecessor, re-run required checks, resolve substantive review state, then return the unchanged verified head to Ready. No commits are closed or discarded.

@seonghobae
seonghobae marked this pull request as draft September 30, 2026 07:04
@seonghobae
seonghobae marked this pull request as ready for review October 2, 2026 15:04

@devin-ai-integration devin-ai-integration Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Devin Review found 1 potential issue.

Devin Review

Comment thread crates/originweave-tls/tests/policy_contract.rs Outdated
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant