fix(#856): the analytics family of draw sites - #1288
Merged
Merged
Conversation
Seven generators across six services move onto IDMint: an Athena query execution ID, a Redshift Data statement ID, a Glue job-run ID, a Timestream QueryId, an OpenSearch document _id and _scroll_id, and a QuickSight ingestion ID and response RequestId. Every rendering is byte-for-byte what crypto/rand produced. What this family adds is the shape of the call the identifier gates. An analytics identifier names a submission rather than a resource, so there is no caller-chosen name to fall back on: GetQueryExecution, GetQueryResults and StopQueryExecution all key on the one ID StartQueryExecution returned, and a re-minted one answered every recorded poll with InvalidRequestException against a query the recording had just created. Redshift Data breaks the same way with ResourceNotFoundException, Glue with EntityNotFoundException, an OpenSearch document read with a 404 and a scroll continuation with search_context_missing_exception. Reverting the Athena minter alone to confirm the replay assertion is not vacuous produces 38 differences and two refused reads out of a 19-request stream. Timestream is the exception and is in the stream for the other half of the property: its QueryId reaches no later call, so a fresh draw there costs a body difference rather than a refusal. IDMint.Base64URL is new, for the one identifier that travels in a URL path: an OpenSearch document id is the path of every later GET, PUT and DELETE of that document, so its alphabet is - and _ rather than + and /. A QuickSight ingestion ID was drawn from the generator that mints the RequestId every response carries - the second instance of the cross-service borrow the ACM/API Gateway split fixed. An ingestion ID is a handle a recorded DescribeIngestion URL contains where a request ID is never sent back, so one function serving both meant a change to how a request ID renders would have moved the identifier a recorded path depends on. A Timestream QueryId is hex where a Redshift Data statement ID is a dashed UUID, and the difference is the published model rather than a preference: API_query_Query constrains QueryId to [a-zA-Z0-9]+, which excludes the hyphen. Neither pattern constrains a position, so both are indifferent to the RFC 4122 version and variant bits, which is why deriving them preserved each rendering instead of quietly setting two nibbles (#671). 11 draw sites remain on crypto/rand.
The scroll refusal is search_context_missing_exception rather than an empty page, and "the same sixteen derived bytes" read as if Timestream and Redshift Data rendered one value two ways rather than each rendering its own.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tier 5 of #856: Athena, Redshift Data, Glue, Timestream, OpenSearch and QuickSight.
Seven generators move onto
IDMint— an Athena query execution ID, a Redshift Data statement ID, aGlue job-run ID, a Timestream
QueryId, an OpenSearch document_idand_scroll_id, and aQuickSight ingestion ID and response
RequestId. Every rendering is byte-for-byte the onecrypto/randproduced, so an identifier a previous substrate recorded is still the shape this onemints.
What this family adds is the shape of the call the identifier gates. An analytics identifier
names a submission rather than a resource, so unlike a bucket or a Glue job there is no
caller-chosen name to fall back on:
GetQueryExecution,GetQueryResultsandStopQueryExecutionall key on the one ID
StartQueryExecutionreturned, and a re-minted one answered every recordedpoll with
InvalidRequestExceptionagainst a query the recording had just created. Redshift Databreaks the same way with
ResourceNotFoundException, Glue withEntityNotFoundException, anOpenSearch document read with a 404 and a scroll continuation with
search_context_missing_exception. Timestream is the exception and is in the stream for the otherhalf of the property: its
QueryIdreaches no later call, so a fresh draw there costs a bodydifference rather than a refusal.
Non-vacuity. Reverting the Athena minter alone produces 38 differences and two refused reads out
of the 19-request stream, which is the check tier 4 ran with
generateVersionID.IDMint.Base64URLis new, for the one identifier that travels in a URL path: an OpenSearchdocument ID is the path of every later
GET,PUTandDELETEof that document, so its alphabet is-and_rather than+and/. Neither the document nor the scroll shape is published by AWS —they are the domain's own REST API, not the
escontrol plane — so substrate's sixteen charactersare a convention it keeps rather than a constraint it meets.
A second cross-service borrow, fixed.
CreateDataSetdrew its SPICE ingestion ID from thegenerator that mints the
RequestIdevery QuickSight response carries. An ingestion ID is a handle arecorded
DescribeIngestionURL contains, where a request ID is observed once and never sent back,so one function serving both meant a change to how a request ID renders would have moved the
identifier a recorded path depends on. Same split #856 made between ACM and API Gateway's API keys.
#671 applied five more times. A Timestream
QueryIdis hex where a Redshift Data statement ID isa dashed UUID, and the difference is the published model:
API_query_QueryconstrainsQueryIdto[a-zA-Z0-9]+, which excludes the hyphen, whileAPI_ExecuteStatementdocumentsIdas a UUID andpublishes the dashed pattern. Neither constrains a position, so both are indifferent to the RFC 4122
version and variant bits. Athena's
QueryExecutionIdpublishes\S+, which decides nothing, andGlue's
JobRunIdadmits nearly any text, so thejr_prefix stays as the service's own convention.11 draw sites remain on
crypto/rand.Verification
make lint(0 issues),make test(race, full suite green), andmake docs-reference-check docs-versions version-check discarded-unmarshal-check wire-bookkeeping-checkwith the ratchet still at 330. Patch coverage is 20/20 changed statements,intersected against
git diff -U0 main.Refs #856.