fix(#856): the CI/CD family of draw sites - #1289
Merged
Merged
Conversation
Five generators across CodeBuild, CodeDeploy and CodePipeline move onto IDMint, so a replayed StartBuild, CreateApplication, CreateDeploymentGroup, CreateDeployment and StartPipelineExecution mint what the recording minted. 6 draw sites remain on crypto/rand. Three renderings of the same sixteen derived bytes coexist here and the published model picks each one. A CodePipeline pipelineExecutionId is the only identifier of the five with a pattern, and the only draw site that set RFC 4122's version and variant bits; the pattern admits any hex digit in either position, so it keeps IDMint.UUID because a consumer validating a version-4 UUID would start failing if the 4 vanished, not because the model requires it. CodeBuild's build ID and CodeDeploy's applicationId and deploymentGroupId publish no pattern at all and did not set those bits, so they keep IDMint.HexUUID (#671). CodeDeploy's deploymentId is the family's one observed shape: the page publishes no pattern, and the d- prefix with nine uppercase alphanumerics comes from AWS's own sample response, d-IIMHK0NHC. An underived build ID stalled a poll loop rather than failing it: BatchGetBuilds reports an unknown ID under buildsNotFound in a 200 with an empty builds list, so a replay answered a wait-for-buildStatus loop with nothing to wait on. The other two addressed identifiers break loudly, with DeploymentDoesNotExistException and PipelineExecutionNotFoundException. Reverting the deployment-ID minter alone produces 10 differences and one refused read out of the 12-request stream, so the replay assertion is not vacuous. Refs #856.
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
6 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Tier 6 of #856. Five generators across CodeBuild, CodeDeploy and CodePipeline move onto
IDMint, soa replayed
StartBuild,CreateApplication,CreateDeploymentGroup,CreateDeploymentandStartPipelineExecutionmint the identifiers the recording minted. 6 draw sites remain oncrypto/rand.Three renderings of one shape, and the published model picks each
codepipeline_plugin.goexecution IDIDMint.UUIDcodebuild_plugin.gobuild IDIDMint.HexUUIDBuild.idpublishes no pattern — String, min length 1 — and the site did not set those bitscodedeploy_plugin.goapplication and deployment-group IDsIDMint.HexUUIDcodedeploy_types.godeployment IDIDMint.Chars(9, …)d-and nine uppercase alphanumerics, observed rather than publishedCodePipeline's pattern —
[0-9a-f]{8}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{4}-[0-9a-f]{12}— admits anyhex digit in the version and variant positions, so it is satisfied by the looser shape too. The
4is kept because a consumer validating the value as a version-4 UUID would start failing if it
vanished, and #856 changes where an identifier comes from rather than which bytes a caller sees.
Per #671, nothing was borrowed the other way: no pattern was invented for the three sites that
publish none.
Provenance
API_CreateDeploymentgivesdeploymentIdas a String with neither a pattern nor lengthconstraints. The
d-prefix and the nine uppercase alphanumeric characters come from the page's ownsample response,
{"deploymentId": "d-IIMHK0NHC"}— reading AWS's example is not theborrowing-a-bound-from-a-sibling that #671 rules out, and it is all the reference offers.
docs/services.mdpreviously called that shape published; this corrects it to observed.
Why an underived ID mattered here
BatchGetBuildsreports an unknown build ID underbuildsNotFoundin a 200 with an emptybuildslist, so a re-minted one did not refuse the recorded read — it answered a consumer'swait-for-
buildStatusloop with nothing to wait on. The other two addressed identifiers breakloudly:
DeploymentDoesNotExistExceptionandPipelineExecutionNotFoundException. CodeDeploy's twoidentity IDs are only reported, so there a fresh draw costs a body difference and a
state_hash_aftermismatch on the create.Tests
TestIDs_TheCICDFamilyKeepsTheRenderingsItsCallersParse— the version nibble and variant bits on apipeline execution ID, and
^d-[A-Z0-9]{9}$on a deployment ID. The tier has no unbounded-drawsite, so this replaces the ordinal-on-a-batch assertion the earlier tiers make.
TestReplay_TheCICDFamilyReplaysWithTheIdentifiersItMinted— a 12-request stream where eachservice's create is followed by the read that can only reach it through the minted handle; zero
differences,
StateValid.Non-vacuity checked numerically: reverting
generateCodeDeployDeploymentIDalone to a seedless mintproduces 10 differences and one refused read out of the 12-request stream, with
DeploymentDoesNotExistExceptionlogged for the recordedGetDeploymentand cascading state-hashdivergence through CodePipeline.
Verification
make lint(0 issues),make test(race, green),make docs-reference-check docs-versions version-check discarded-unmarshal-check wire-bookkeeping-check— wire-bookkeeping ratchet still 330.Patch coverage 10/10 changed statements, intersected against
git diff -U0 main.Refs #856.