fix(#856): the compute and edge family of identifier draw sites - #1284
Merged
Merged
Conversation
Eleven generators across nine plugin files move onto IDMint: API Gateway (v1 and v2), AppSync, Batch, EMR Serverless, ECR, ELB and Route 53. The shared UUID-shape renderer is promoted to IDMint.HexUUID and its thirteen call sites rewritten, so a Batch job id is no longer minted by a function named generateLambdaRevisionID. An API Gateway id can now contain a digit: the crypto/rand version mapped each nibble of five bytes through the 36-character alphabet, so only `a` through `p` could appear. Drawing a byte per character reaches the whole published set. 23 draw sites remain on crypto/rand. Refs #856.
6 tasks done
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tier 3 of #856 — the compute and edge family. Eleven generators across nine plugin files move onto
IDMint, so a replayed create in API Gateway (v1 and v2), AppSync, Batch, EMR Serverless, ECR, ELBor Route 53 mints the identifier its recording minted.
The shared UUID-shape renderer moves to the seam
Batch job IDs and EMR Serverless job-run IDs publish the same
8-4-4-4-12lowercase-hex renderingthe six services in the previous tier do, and the helper they would have called was declared in
lambda_plugin.goand namedgenerateLambdaRevisionID. Rather than add a third copy of the sliceor have Batch call a Lambda-named function, it is promoted to
IDMint.HexUUID()and its thirteencall sites rewritten; the old function is deleted. The rendering is byte-for-byte unchanged — it
deliberately does not set the RFC 4122 version and variant bits, because #856 is about
reproducing an identifier across a replay and not about changing which bytes a caller sees.
One alphabet changed, and widened
An API Gateway ID is ten lowercase alphanumeric characters. The
crypto/randversion read fivebytes and mapped each nibble through the 36-character alphabet, so only
athroughpcouldever appear and a digit never did.
IDMint.Charsdraws a byte per character and reaches the wholepublished set, so an API, resource, deployment, authorizer or usage-plan ID — and an API Gateway v2
route, integration or mapping ID — now looks like one AWS would issue. This is the only identifier
in the tier whose rendering changed at all, and the change is a fix rather than a cost;
TestIDMint_TheAPIGatewayAlphabetIsTheWholePublishedSetpins it against a fixed seed rather thanasserting it in prose.
Two doc comments in
appsync_types.goclaimed widths their code never produced (randomHex(13)documented as 13 hex characters, which is 26); they now state what the function returns.
Tests
TestReplay_TheComputeAndEdgeFamiliesReplayWithTheIdentifiersTheyMintedrecords one interlockedstream across all seven services — a REST API plus a resource under the root ID the create handed
back and a deployment; an AppSync API, key and function read back by the minted function ID; a
hosted zone and a record-set change inside it; a load balancer, a target group and a listener naming
both ARNs; a Batch job described by its job ID; an EMR Serverless application and a job run fetched
under both; an ECR repository and an image fetched by the digest the push minted — and asserts
TotalEvents == SuccessEvents, noDifferences, andStateValidtrue with recorded state hashes.Every later request names what an earlier one minted, which is what makes the stream an assertion
rather than a smoke test. The assertion was checked for vacuity by reverting
generateELBSuffixtorandomHexalone: the replay then reports 28 differences across four ARN fields and the state-hashcascade behind them.
Two ordinal tests cover the per-request advance — one
CreateRestApimints an API ID distinct fromits root resource ID, one
CreateHostedZonea zone ID distinct from its change ID.Not in this PR, recorded rather than silent
manifest bytes store two images where AWS stores one. That is a change to what the digest means
rather than to where its bytes come from, and several existing tests push a shared
{"schemaVersion":2}manifest and expect distinct images — filed as ECR: an image digest should be the SHA-256 of the manifest, not a minted value #1283, and referenced fromthe code comment so the observation is not lost.
ec2_plugin.go:879mints anAIPA…instance-profile ID on a describe path, so twodescribes of one instance report different IDs. Identifiers minted from crypto/rand make a replay diverge from its recording, and three replay checks are weakened for it #856's own comment files this separately: giving
it the request's mint would make it replay-stable and still wrong.
23 draw sites remain on
crypto/rand, tiered by family on the issue. #856 stays open until thatlist empties.
Refs #856.