Repository navigation
Conversation
Map only typed Prost decode errors at generated server request boundaries. Keep generated client response decoding, framing/compression statuses, message caps and response encoding unchanged, including DAPI's server-feature Drive client. Valid application requests, stored roots and proofs retain their behavior; this transport correction does not affect consensus or replay. Test would have caught this in CI: ✖ before fix, ✔ after. Observed runtime RED→GREEN on identical raw-transport regression files: Core/DriveInternal 1 failed and 2 passed→3 passed, real DAPI forwarding 2 failed and 2 passed→4 passed, real Drive 1 failed and 1 passed→2 passed. Final tests and neighboring query-error controls pass on current upstream. Generated client/messages/descriptors remain identical; native and wasm SDK consumers compile.
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
⛔ Files ignored due to path filters (1)
📒 Files selected for processing (12)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📝 WalkthroughWalkthroughThe server build now uses a custom Prost request decoder that maps protobuf decode failures to ChangesProtobuf Request Decode Errors
Priority: ➖ Normal Estimated code review effort: 3 (Moderate) | ~25 minutes Change: Bug fix Sequence Diagram(s)sequenceDiagram
participant RawGrpcClient
participant CoreGrpcService
participant RequestDecoder
participant CoreHandler
RawGrpcClient->>CoreGrpcService: Send request payload
CoreGrpcService->>RequestDecoder: Decode protobuf payload
alt Payload is malformed
RequestDecoder-->>CoreGrpcService: Return INVALID_ARGUMENT
CoreGrpcService-->>RawGrpcClient: Return decode error
else Payload is valid
RequestDecoder-->>CoreGrpcService: Return decoded request
CoreGrpcService->>CoreHandler: Invoke handler
end
Suggested reviewers: Merge Risk: ⚪ Minimal · up to Malformed protobuf requests now return an invalid-argument error rather than an internal error, so callers can avoid retrying or banning healthy nodes. The rest of the change is tests, and no merge-blocking risk is evident. 🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)✅ Passed checks (4 passed)Full details: Docstring CoverageExplanation Docstring coverage is 22.58% which is insufficient. The required threshold is 80.00%. Docstring coverage is scoped to functions touched by this diff. Analyzed 62 functions across 9 files. (3 skipped: 3 unsupported.)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
✅ Final review complete — no blockers (commit 1b34e74) · triage: normal |
|
@coderabbitai review |
✅ Action performedReview finished.
|
|
The docstring-coverage warning counts private test fixtures and trait implementations. This change adds no public API; the codec module and generation comments explain the request/response boundary, and the offline construction helpers already have documentation. Following the surrounding repository conventions, no boilerplate comments were added solely to raise that ratio. The advisory warning remains; it is not reported as passed. |
|
Waiting for bot review — coderabbitai ✓ · thepastaclaw not yet. Wait for the missing reviews, or a writer can post |
thepastaclaw
left a comment
There was a problem hiding this comment.
Final validation — Phase 1 + Phase 2
The server request codec maps Prost payload-decoding failures to INVALID_ARGUMENT while preserving the existing response encoder and client response decoding. Static inspection of the exact PR head confirms the transport boundary and regression fixtures support the stated goal; no actionable in-scope findings remain. No builds or tests were run in this lane, and the supplied CI snapshot shows Rust workspace tests skipped with other checks still queued, pending, or in progress.
Review provenance
Source: reviewer 1: gemini-3.8-flash-high (agent: phase1-reviewer, role: general); reviewer 2: gemini-3.8-flash-high (agent: phase1-reviewer, role: rust-quality); reviewer 3: gpt-6.1-sol (agent: phase2-reviewer, role: general); reviewer 4: gpt-6.1-sol (agent: phase2-reviewer, role: architecture-layering); reviewer 5: gpt-6.1-sol (agent: phase2-reviewer, role: rust-quality); reviewer 6: gpt-6.1-sol (agent: phase2-reviewer, role: security-auditor); final verifier: gpt-6.1-sol (agent: sol-verifier, role: final-verifier)
- Triage:
normalbygpt-6.1-sol(effort low) — The production change is a contained server-side protobuf error mapping with direction-specific code generation, not a large or intricate change to network deserialization despite the extensive regression tests. - Phase 1 reviewers:
gemini-3.8-flash-high— general (completed, effort high); agentphase1-reviewer,gemini-3.8-flash-high— rust-quality (completed, effort high); agentphase1-reviewer - Phase 1 model:
gemini-3.8-flash-high— antigravity quota: weekly 81% left, 5h 80% left - Fresh verifier:
gpt-6.1-sol— final-verifier; agentsol-verifier - Phase 2 reviewers:
gpt-6.1-sol— general (completed, effort high); agentphase2-reviewer,gpt-6.1-sol— architecture-layering (completed, effort high); agentphase2-reviewer,gpt-6.1-sol— rust-quality (completed, effort high); agentphase2-reviewer,gpt-6.1-sol— security-auditor (completed, effort high); agentphase2-reviewer
|
Bots are done — your move: post |
Basic explanation
What this does: Return
INVALID_ARGUMENTwhen a caller supplies undecodable protobuf in an otherwise accepted gRPC message. Corrupt node responses still returnINTERNAL.Value: Callers receive a request error, and the existing SDK stops without retrying or banning a healthy node. No SDK policy change is needed.
Risks: The externally visible request status changes deliberately. Generated clients, message types and descriptors retain their existing output; deterministic transport and proof controls cover the direction boundary. No consensus or stored-state change.
Issue being fixed or feature implemented
The Sakura audit reports malformed protobuf as
INTERNAL. This is gRPC's library convention; this PR deliberately applies the caller-error policy at the server request decoder. Reconstructed malformed inputs reproduce the reported status locally; the original private campaign scripts are unavailable.What was done?
INVALID_ARGUMENT, retaining its description and the existing response encoder.ProstCodec, including DAPI's Drive client when server features are enabled.cfg(test)only.In-place changes to shipped generations
This boundary runs before a request reaches a query or state-transition handler. Undecodable outer protobuf cannot affect block execution; valid requests, application state, replay inputs, proof format and verified roots are unchanged. Native Client and WASM generation are untouched, so no new consensus generation or protocol table is required. Older binaries retain the old status; this PR does not establish deployment or historical repair.
How Has This Been Tested?
Actual red→green on identical regression files before/after the decoder change: generated services 1 failed / 2 passed → 3 passed, real DAPI forwarding 2 failed / 2 passed → 4 passed, real Drive 1 failed / 1 passed → 2 passed. The passing baseline controls include real corrupt-response bytes, valid calls, original-query proofs and exact stored roots. Final test cleanup only removes an unused import, adds the Core feature gate and factors the stream type.
cargo test -p dapi-grpc --all-features --tests --locked -j 2: malformed tags/varints/lengths/UTF-8, no handler invocation, stream refusal/termination, unknown fields, framing/compression and cap controls.cargo test -p rs-dapi --lib services::platform_service:: --locked -j 2: 74 passing tests on parentb49f382949, including all four regressions and neighboring error mappings. After safely fast-forwarding toecfc96d44a, the focusedservices::platform_service::protobuf_request_errorsselection passed all four again. Actual DAPI receives raw malformed caller messages and actual corrupt Drive response bytes. Executor retry/ban controls replay the exact served status through the real DapiClient; they are not a second SDK wire-transport test.cargo test -p drive-abci --test protobuf_request_errors --test query_request_errors --locked -j 2: five passing tests, including present/absent canonical data, original-query proof/root verification and caller/node-failure controls.b49f382949: native server/client/transport/serde/mocks and wasm32 client generation checks; native DAPI/Drive/DAPI-client/Rust-SDK and wasm32 WASM-SDK consumer checks. Upstream advancement left these owned boundaries unchanged. The WASM-SDK check uses target-specific installed LLVM CC/AR through sccache; the initial Apple-clang attempt lacked a wasm32 target.ecfc96d44a. CI provides the pinned cargo-machete tool, which is unavailable locally, and checks all targets on the clean PR head.All transport tests use in-memory duplexes and deterministic fixtures, with no live network requests.
Breaking Changes
No schema or API-shape changes. Malformed caller protobuf intentionally changes from
INTERNALtoINVALID_ARGUMENT; node-failure statuses retain their existing retry semantics.Checklist:
structure.rs, regeneratedgrovedb-structure.json, and checked the structure viewer link posted on this pull requestFor repository code-owners and collaborators only
Summary by CodeRabbit
InvalidArgumenterror without being processed or changing Drive state.PR Hygiene ·
1b34e74/self-reviewedrust-dapi(packages/rs-dapi/Cargo.toml,packages/rs-dapi/src/clients/drive_client.rs,packages/rs-dapi/src/clients/tenderdash_client.rsand 2 more) — QuantumExplorer or lklimekrs-drive-abci— you own itWhen every merge requirement is met, the
PR Hygienecheck passes. Reviewer limits do not block merging; other required GitHub checks and protections still apply.