test(review 009): all seven coverage findings; errata on three as-filed claims
Review 009's coverage debt in full — the paths the review-008 gates
never walk. No wire or API changes.
- C-1: pin the plain-bundle install-failure arm (un-compilable
input_schema; the as-filed duplicate-name route does not fail
registration) — the install task ends before the dispatch loop,
channel 0 never dispatches. ADR-051 §5 gains the loud-install
coverage note: relay-openable + plain-bundle arms pinned,
generic-ops + bootstrap-discovery arms documented as
best-effort-loud (crate-internal specs compile by construction).
- C-2: the HubLegImports filter — filtered closure path + only
partition unit-tested (errata: only was already pinned at filing);
the empty-stash e2e gate (generic ops + discovery only, dropped
ops resolve NOT_FOUND).
- C-3: the batch-form reserved-reply-key rejection pinned (reason
handler_error, teardown, ledger decrement, no pump spawn).
- C-4: open_channel_with_reply's failure path pinned e2e (the typed
error carries the channel:open_failed code + details reason/message).
- C-5: both byte-identical claims golden-pinned — the no-fields reply
against {"channel_id": 2} and the standard-shape wire payload
against the full 9-key literal.
- C-6: derivation edge shapes pinned — channels//sub, channels//direct,
channels → None; the 4-segment strict superset annotated as the
pre-amendment behavior change (errata: actual is Some("x/sub"), the
multi-segment-ALPN rule, not the as-filed Some("alk/x/sub")).
- C-7: builder overwrite pinned last-win (single + batch) with the
doc sentence on with_reply_field.
Verification: 682 tests pass, clippy -D warnings clean, fmt clean,
doc clean, wasm32 check clean.
File: docs/reviews/009 (resolved; errata marked per finding)
This commit is contained in:
1 parent
54c2a3f941
commit
9620ee7b2a
7 files changed
+594
-1
No files matched your search
@@ -189,6 +189,20 @@ spec's ACL (+ hub policy) on the consumer leg; the spoke-side grant
|
||||
goes to the hub identity, which needs scopes on every spoke op it
|
||||
relays. The end consumer never authenticates to the spoke directly.
|
||||
|
||||
**Loud-install coverage note (review 009 C-1):** the template's four
|
||||
install-failure arms all end the install task before the dispatch
|
||||
loop (channel 0 never dispatches — never a silent stub). Two arms are
|
||||
unit-test-pinned: the relay-openable registration failure (the
|
||||
Pub-typed marked spec gate) and the plain-bundle registration failure
|
||||
(an un-compilable schema — the registry's fail-closed rule). The
|
||||
other two arms — generic channel-ops registration and bootstrap
|
||||
discovery install — are best-effort-loud: both register
|
||||
crate-internal specs whose schemas compile by construction, so
|
||||
failure is not reachable through any public path and an injectable
|
||||
failure seam would test the seam, not the arm. This note is the
|
||||
contract: if a future change makes either arm reachable, it gets the
|
||||
same pin.
|
||||
|
||||
### 6. Bounds: rejected shapes and residual notes
|
||||
|
||||
- **Pub-typed open ops** — rejected loudly (`channel:pub_open_not_implemented`,
|
||||
|
||||
@@ -2,6 +2,16 @@
|
||||
|
||||
## Status
|
||||
|
||||
Resolved — all seven findings landed in alkcall 0.8.0 (2026-09-18,
|
||||
same working tree as the audit's inline fixes): C-1 (plain-bundle arm
|
||||
pinned + the ADR-051 §5 coverage note), C-2 (`filtered` closure unit +
|
||||
the empty-stash e2e gate), C-3 (the batch-form reserved key), C-4
|
||||
(the `open_channel_with_reply` failure path), C-5 (both golden pins),
|
||||
C-6 (the derivation edge shapes), C-7 (last-win pinned + the doc
|
||||
sentence). Three errata on the as-filed text (marked per finding).
|
||||
No wire or API changes were needed. Verified at resolution: 680
|
||||
tests pass, clippy/fmt clean, wasm check clean.
|
||||
|
||||
Open — filed 2026-09-18 from the post-landing audit of the six commits
|
||||
`82ddddf..50182d7` (review 008's three units). Scope: correctness
|
||||
review of the full diff, test-coverage mapping, and the classic
|
||||
@@ -34,6 +44,18 @@ walk.
|
||||
|
||||
## C-1: `HubLegTemplate::install_hook` failure arms are loud-only-in-code
|
||||
|
||||
**Errata (2026-09-18, at resolution).** The as-filed route (a) —
|
||||
"a duplicate name between a plain bundle and the generic channel ops"
|
||||
— does not fail `OperationRegistry::register` (same-name registration
|
||||
overwrites; the map is an insert). The honest failure mechanism used
|
||||
is the registry's other fail-closed rule: an un-compilable
|
||||
`input_schema` (`{"type": "object", "required": "not-an-array"}`,
|
||||
the CF-003 shape). Resolved with route (c)'s documentation half for
|
||||
the generic-ops/bootstrap-discovery arms: ADR-051 §5 now carries the
|
||||
loud-install coverage note (two arms pinned, two arms
|
||||
best-effort-loud — the crate-internal specs compile by construction,
|
||||
so an injectable seam would test the seam, not the arm).
|
||||
|
||||
**Finding.** `src/channels/hub_leg.rs:232-275` — four install arms end
|
||||
the leg with only a `tracing::warn!`: generic channel ops registration
|
||||
failure, plain-bundle registration failure, relay-openable
|
||||
@@ -65,6 +87,14 @@ best-effort-loud, so the ADR and the code say the same thing.
|
||||
|
||||
## C-2: `HubLegImports::filtered` / `only` have no test
|
||||
|
||||
**Errata (2026-09-18, at resolution).** The as-filed "no unit test"
|
||||
overstated: `stash_filter_keeps_named_ops_only` (landed with Unit 3b)
|
||||
already exercised `only` at filing time. The real gaps — the
|
||||
`filtered` closure path and the empty-filter e2e shape — are what
|
||||
landed (`stash_only_keeps_the_marked_direct_spec_and_drops_the_rest`,
|
||||
`stash_filtered_closure_partitions_both_halves`,
|
||||
`template_empty_only_stash_installs_generic_ops_and_discovery_only`).
|
||||
|
||||
**Finding.** `src/channels/hub_leg.rs:91-111` — the per-consumer
|
||||
op-subset filter, the mechanism behind ADR-051 §4's "per-consumer ACL
|
||||
differentiation is a composition consequence" note, has no unit test.
|
||||
@@ -151,6 +181,15 @@ claims the ADRs advertise as wire-stable.
|
||||
|
||||
## C-6: `derive_alpn_from_op_name` edge shapes unpinned
|
||||
|
||||
**Errata (2026-09-18, at resolution).** The as-filed expectation
|
||||
`"channels/x/sub/extra"` → `Some("alk/x/sub")` mis-stated the actual
|
||||
behavior: the last-segment strip yields `rest = "x/sub/extra"`, and
|
||||
`x/sub` (multi-segment, non-`alk/*`) rides as a full ALPN per the
|
||||
ALPNs-without-the-prefix rule — `Some("x/sub")`, the same rule the
|
||||
existing 5-segment test (`vendor/service/run`) pins. The landed test
|
||||
asserts the actual behavior with the behavior-change-vs-pre-amendment
|
||||
annotation.
|
||||
|
||||
**Finding.** `src/client/from_call.rs:326-337` — the empty-segment
|
||||
guard (`segment.is_empty()`) and the bare-no-slash name have no unit
|
||||
test, and the 4-segment name behavior *changed* (pre-amendment:
|
||||
|
||||
Reference in new issue
Block a user