Skip to content

fix(#856): the compute and edge family of identifier draw sites - #1284

Merged
scttfrdmn merged 1 commit into
mainfrom
fix/856-compute-edge-ids
Sep 26, 2026
Merged

scttfrdmn merged 1 commit into
mainfrom
fix/856-compute-edge-ids

Conversation

@scttfrdmn

Copy link
Copy Markdown
Owner

Tier 3 of #856 — the compute and edge family. Eleven generators across nine plugin files move onto
IDMint, so a replayed create in API Gateway (v1 and v2), AppSync, Batch, EMR Serverless, ECR, ELB
or Route 53 mints the identifier its recording minted.

The shared UUID-shape renderer moves to the seam

Batch job IDs and EMR Serverless job-run IDs publish the same 8-4-4-4-12 lowercase-hex rendering
the six services in the previous tier do, and the helper they would have called was declared in
lambda_plugin.go and named generateLambdaRevisionID. Rather than add a third copy of the slice
or have Batch call a Lambda-named function, it is promoted to IDMint.HexUUID() and its thirteen
call sites rewritten; the old function is deleted. The rendering is byte-for-byte unchanged — it
deliberately does not set the RFC 4122 version and variant bits, because #856 is about
reproducing an identifier across a replay and not about changing which bytes a caller sees.

One alphabet changed, and widened

An API Gateway ID is ten lowercase alphanumeric characters. The crypto/rand version read five
bytes and mapped each nibble through the 36-character alphabet, so only a through p could
ever appear and a digit never did. IDMint.Chars draws a byte per character and reaches the whole
published set, so an API, resource, deployment, authorizer or usage-plan ID — and an API Gateway v2
route, integration or mapping ID — now looks like one AWS would issue. This is the only identifier
in the tier whose rendering changed at all, and the change is a fix rather than a cost;
TestIDMint_TheAPIGatewayAlphabetIsTheWholePublishedSet pins it against a fixed seed rather than
asserting it in prose.

Two doc comments in appsync_types.go claimed widths their code never produced (randomHex(13)
documented as 13 hex characters, which is 26); they now state what the function returns.

Tests

TestReplay_TheComputeAndEdgeFamiliesReplayWithTheIdentifiersTheyMinted records one interlocked
stream across all seven services — a REST API plus a resource under the root ID the create handed
back and a deployment; an AppSync API, key and function read back by the minted function ID; a
hosted zone and a record-set change inside it; a load balancer, a target group and a listener naming
both ARNs; a Batch job described by its job ID; an EMR Serverless application and a job run fetched
under both; an ECR repository and an image fetched by the digest the push minted — and asserts
TotalEvents == SuccessEvents, no Differences, and StateValid true with recorded state hashes.
Every later request names what an earlier one minted, which is what makes the stream an assertion
rather than a smoke test. The assertion was checked for vacuity by reverting generateELBSuffix to
randomHex alone: the replay then reports 28 differences across four ARN fields and the state-hash
cascade behind them.

Two ordinal tests cover the per-request advance — one CreateRestApi mints an API ID distinct from
its root resource ID, one CreateHostedZone a zone ID distinct from its change ID.

Not in this PR, recorded rather than silent

23 draw sites remain on crypto/rand, tiered by family on the issue. #856 stays open until that
list empties.

Refs #856.

Eleven generators across nine plugin files move onto IDMint: API Gateway
(v1 and v2), AppSync, Batch, EMR Serverless, ECR, ELB and Route 53.

The shared UUID-shape renderer is promoted to IDMint.HexUUID and its
thirteen call sites rewritten, so a Batch job id is no longer minted by a
function named generateLambdaRevisionID.

An API Gateway id can now contain a digit: the crypto/rand version mapped
each nibble of five bytes through the 36-character alphabet, so only `a`
through `p` could appear. Drawing a byte per character reaches the whole
published set.

23 draw sites remain on crypto/rand.

Refs #856.
@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@scttfrdmn
scttfrdmn merged commit ad53aea into main Sep 26, 2026
18 checks passed
@scttfrdmn
scttfrdmn deleted the fix/856-compute-edge-ids branch September 26, 2026 08:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant