Skip to content

fix(#856): the CI/CD family of draw sites - #1289

Merged
scttfrdmn merged 1 commit into
mainfrom
fix/856-cicd-draw-sites
Sep 26, 2026
Merged

scttfrdmn merged 1 commit into
mainfrom
fix/856-cicd-draw-sites

Conversation

@scttfrdmn

Copy link
Copy Markdown
Owner

Tier 6 of #856. Five generators across CodeBuild, CodeDeploy and CodePipeline move onto IDMint, so
a replayed StartBuild, CreateApplication, CreateDeploymentGroup, CreateDeployment and
StartPipelineExecution mint the identifiers the recording minted. 6 draw sites remain on
crypto/rand.

Three renderings of one shape, and the published model picks each

Site Rendering Why
codepipeline_plugin.go execution ID IDMint.UUID The family's only published pattern, and the only draw site that set RFC 4122's version and variant bits
codebuild_plugin.go build ID IDMint.HexUUID Build.id publishes no pattern — String, min length 1 — and the site did not set those bits
codedeploy_plugin.go application and deployment-group IDs IDMint.HexUUID Neither publishes a pattern or length constraints
codedeploy_types.go deployment ID IDMint.Chars(9, …) d- and nine uppercase alphanumerics, observed rather than published

CodePipeline's pattern — [0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12} — admits any
hex digit in the version and variant positions, so it is satisfied by the looser shape too. The 4
is kept because a consumer validating the value as a version-4 UUID would start failing if it
vanished, and #856 changes where an identifier comes from rather than which bytes a caller sees.
Per #671, nothing was borrowed the other way: no pattern was invented for the three sites that
publish none.

Provenance

API_CreateDeployment gives deploymentId as a String with neither a pattern nor length
constraints. The d- prefix and the nine uppercase alphanumeric characters come from the page's own
sample response, {"deploymentId": "d-IIMHK0NHC"} — reading AWS's example is not the
borrowing-a-bound-from-a-sibling that #671 rules out, and it is all the reference offers. docs/services.md
previously called that shape published; this corrects it to observed.

Why an underived ID mattered here

BatchGetBuilds reports an unknown build ID under buildsNotFound in a 200 with an empty
builds list, so a re-minted one did not refuse the recorded read — it answered a consumer's
wait-for-buildStatus loop with nothing to wait on. The other two addressed identifiers break
loudly: DeploymentDoesNotExistException and PipelineExecutionNotFoundException. CodeDeploy's two
identity IDs are only reported, so there a fresh draw costs a body difference and a
state_hash_after mismatch on the create.

Tests

  • TestIDs_TheCICDFamilyKeepsTheRenderingsItsCallersParse — the version nibble and variant bits on a
    pipeline execution ID, and ^d-[A-Z0-9]{9}$ on a deployment ID. The tier has no unbounded-draw
    site, so this replaces the ordinal-on-a-batch assertion the earlier tiers make.
  • TestReplay_TheCICDFamilyReplaysWithTheIdentifiersItMinted — a 12-request stream where each
    service's create is followed by the read that can only reach it through the minted handle; zero
    differences, StateValid.

Non-vacuity checked numerically: reverting generateCodeDeployDeploymentID alone to a seedless mint
produces 10 differences and one refused read out of the 12-request stream, with
DeploymentDoesNotExistException logged for the recorded GetDeployment and cascading state-hash
divergence through CodePipeline.

Verification

make lint (0 issues), make test (race, green), make docs-reference-check docs-versions version-check discarded-unmarshal-check wire-bookkeeping-check — wire-bookkeeping ratchet still 330.
Patch coverage 10/10 changed statements, intersected against git diff -U0 main.

Refs #856.

Five generators across CodeBuild, CodeDeploy and CodePipeline move onto
IDMint, so a replayed StartBuild, CreateApplication,
CreateDeploymentGroup, CreateDeployment and StartPipelineExecution mint
what the recording minted. 6 draw sites remain on crypto/rand.

Three renderings of the same sixteen derived bytes coexist here and the
published model picks each one. A CodePipeline pipelineExecutionId is the
only identifier of the five with a pattern, and the only draw site that
set RFC 4122's version and variant bits; the pattern admits any hex digit
in either position, so it keeps IDMint.UUID because a consumer validating
a version-4 UUID would start failing if the 4 vanished, not because the
model requires it. CodeBuild's build ID and CodeDeploy's applicationId
and deploymentGroupId publish no pattern at all and did not set those
bits, so they keep IDMint.HexUUID (#671). CodeDeploy's deploymentId is
the family's one observed shape: the page publishes no pattern, and the
d- prefix with nine uppercase alphanumerics comes from AWS's own sample
response, d-IIMHK0NHC.

An underived build ID stalled a poll loop rather than failing it:
BatchGetBuilds reports an unknown ID under buildsNotFound in a 200 with
an empty builds list, so a replay answered a wait-for-buildStatus loop
with nothing to wait on. The other two addressed identifiers break
loudly, with DeploymentDoesNotExistException and
PipelineExecutionNotFoundException. Reverting the deployment-ID minter
alone produces 10 differences and one refused read out of the
12-request stream, so the replay assertion is not vacuous.

Refs #856.
@codecov

codecov Bot commented Sep 26, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.

📢 Thoughts on this report? Let us know!

@scttfrdmn
scttfrdmn merged commit 2c90f4e into main Sep 26, 2026
18 checks passed
@scttfrdmn
scttfrdmn deleted the fix/856-cicd-draw-sites branch September 26, 2026 15:02
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant